[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> Grok chat duped into swallowing injected instructions
A spoonful of encryption helps the malware go down
> NCSC Urges Stronger Controls for Agentic AI Systems
NCSC urged sandboxing, oversight and tight access controls for autonomous AI agents
> Your Mac already has a built-in firewall. Here’s how to get more from it 
Malwarebytes Firewall gives you a clearer, more intuitive way to manage your Mac's inbuilt firewall.
> US says hackers are targeting vulnerable water systems with the help of AI
Hackers are targeting internet-connected Siemens controllers used in water facilities around the United States.
> US Defense Contractors Admit Their Rising CMMC Scores May Not Be Accurate
Defense contractors in the US are doubting their own self-assessment scores under CMMC Phase I, even as those scores hit an all-time high
> French tax authority says break-in exposed data of 600K, including some private messages
Stolen details range from contact information to household finances and withholding rates
> Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities
The flaws could be exploited to execute arbitrary code, access sensitive information, and elevate privileges. The post Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities appeared first on SecurityWeek.
> Citrix urges admins to patch new NetScaler flaws as soon as possible
Citrix has warned customers to immediately secure their systems against two vulnerabilities affecting NetScaler Gateway secure remote access solutions and NetScaler ADC networking appliances. [...]
> MLflow Vulnerability Exploited for Cloud Credential Theft
The critical-severity flaw allows attackers to send HTTP requests to internal endpoints and extract sensitive information. The post MLflow Vulnerability Exploited for Cloud Credential Theft appeared first on SecurityWeek.
> Fuite Stripe : au moins 200 Français concernés
Fuite Stripe : ZATAZ confirme au moins 200 Français concernés et propose une vérification gratuite et humaine.
> Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments
Researchers at the University of Massachusetts Amherst have demonstrated an attack that revives expired Visa contactless credit cards for real in-store purchases by rewriting the expiration date a point-of-sale (POS) terminal reads over near-field communication (NFC), without breaking any of the car...
> Kriminal breaks out of Grok, Claude guardrails at $12.99
Security researchers are warning of a criminal AI service built on Grok and Claude, among other models, that promises uncensored access to powerful AI capabilities for as little as $12.99 a month. ThreatDown researchers say “Kriminal” is largely a storefront wrapped around...
> Managing the cyber risk of agentic AI
Use safeguards, sandboxing and active oversight to realise the benefits of autonomous systems while limiting the unintended activity.
> Impact, Coping And Support – Further Reflections From The DFIR Well-Being Study
What does repeated exposure to traumatic digital evidence really do to investigators? Phil Anderson returns to the Forensic Focus Podcast to unpack more findings from the international well-being study.
> 9 million images of people’s faces exposed by reverse lookup service
A researcher found an exposed database containing 9 million images that belonged to people finder service ClarityCheck.
> Using Microsoft Graph and Powershell to Mine for Information - Stale Accounts and Licenses, (Thu, Aug 20th)
Microsoft Graph is a newer API that is meant to replace several others.&#;x26;#;xc2;&#;x26;#;xa0; OK, it&#;x26;#;39;s at version 2.3.9, so it&#;x26;#;39;s not all that new, but it&#;x26;#;39;s new enough that lots of folks (and commercial tools) aren&#;x26;#;39;t using it yet...
> Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities
The flaws could lead to remote code execution, authentication bypasses, and path traversal attacks. The post Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities appeared first on SecurityWeek.
> Why "Shady AI" is Security's Next Big Governance Problem
In March 2026, an internal AI agent at Meta triggered a “Sev 1” incident after sensitive company and user data was exposed to employees who weren’t authorized to access it.  The incident began when a Meta employee posted a technical question on an internal forum. An engineer used an approved AI age...
> USN-8653-1: PostgreSQL vulnerabilities
It was discovered that PostgreSQL incorrectly handled COPY FROM STDIN when an early failure occurred. An authenticated user could possibly use this issue to execute arbitrary SQL commands. (CVE-2026-6464) It was discovered that PostgreSQL incorrectly reset extended statistics ownership during ALTER...
> CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification
Cybersecurity researchers have disclosed two denial-of-service (DoS) attacks that exploit how major content delivery networks (CDNs) convert client-facing HTTP/3 traffic into HTTP/1.1 requests to the websites they front, amplifying a low-bandwidth request stream by up to 350x against the origin serv...