[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices
A new Android threat codenamed Manic has been observed actively targeting Ukrainian banks, government and identity services, and messaging applications, as well as Russian and European financial institutions, global fintech and cryptocurrency services, and military-focused communications. "Manic si...
> Corero brings cloud-based AI threat analysis to SmartWall ONE
Corero Network Security has announced AI-Augmented Cloud-Assist for SmartWall ONE, extending its automated DDoS protection with cloud-delivered AI analysis, threat intelligence, and policy optimization. As cybercriminals increasingly leverage AI to develop and evolve attack campaigns, defenders must...
> AWS limits AI agents’ data access, even when manipulated
AWS has detailed an approach for propagating user authorization context through AI agents, allowing access controls to be enforced by infrastructure and downstream services rather than relying on the agent itself. Customers using Amazon Bedrock AgentCore can build AI agents that pull information fro...
> AI-Assisted Tool Helped Secure Satellite Communication System After 2022 Russian Hacking
Atalanta's Argo product is now being used to prove the resilience of Viasat’s satellite communications network. The post AI-Assisted Tool Helped Secure Satellite Communication System After 2022 Russian Hacking appeared first on SecurityWeek.
> CISA warns of hackers exploiting critical MLflow vulnerability
The Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies that threat actors are now exploiting a critical vulnerability in the MLflow open-source AI engineering platform. [...]
> What the EU AI Act means for you and your business
The EU AI Act is changing how AI can be used in Europe. Learn what’s banned, what’s regulated, and what it means for you or your business.
> NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands
Security researchers at Cycode have disclosed a chain of flaws in AIT-GUI, the browser-based operator console for NASA/JPL's open-source AMMOS Instrument Toolkit, that allow an unauthenticated attacker to issue arbitrary commands to the software's spacecraft and instrument command bus. The chain, t...
> Geekom : un pilote réseau malveillant était téléchargeable depuis son site de support
L'installation du pilote réseau de 6 mini PC Geekom est détecté comme malveillant par 4 plateformes d'analyse, mais tous les PC ne sont pas infectés. Le post Geekom : un pilote réseau malveillant était téléchargeable depuis son site de support a été publié sur IT-Connect.
> ICS Operators Warned of AI-Driven Attacks on Siemens PLCs
A US government advisory warned that attackers are deploying AI-generated exploitation scripts against exposed Siemens S7 Series PLCs
> Fake Gemini installer delivers Vidar infostealer via Google Colab lure
A malicious executable masquerading as a Google Gemini installer was used to deliver the Vidar infostealer on a company network in the EMEA region, according to Darktrace researchers who investigated the incident. “During the initial analysis, it was noted that the top search result for the suspicio...
> Infosec News Nuggets — August 20, 2026
CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE CISA added a critical flaw in the open-source Ray distributed computing framework to its Known Exploited Vulnerabilities catalog after confirming active exploitation. The bug, rated 9.4 in severity, stems from Ray’s lack of au...
> ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud
Cybersecurity researchers have shed light on an updated version of ToxicPanda (aka TgToxic) that comes with "significant enhancements," including a set of 167 remote commands and expands its targeting footprint globally. Zimperium zLabs, in a Wednesday report, said the Android malware also features...
> OpenAI Overhauls Model Security With Sandboxing, 30-Minute Alerts, and Training Pauses
The action taken by OpenAI comes in light of the Hugging Face incident and the discovery of the Astra model’s advanced capabilities.  The post OpenAI Overhauls Model Security With Sandboxing, 30-Minute Alerts, and Training Pauses appeared first on SecurityWeek.
> Oracle Linux MySQL 8.4 Important Bug Fix Advisory ELSA-2026-56007
Oracle Linux 10 has new MySQL 8.4.11 packages addressing multiple CVEs, enhancing security. The updates include various components for x86_64 and aarch64 architectures available via the Unbreakable Linux Network.
> Oracle Linux PHP 8.4 Important Bug Fix Advisory ELSA-2026-56969
Oracle Linux has released updates for PHP 8.4.24 addressing CVEs 2026-17543 and 2026-17544, with new RPMs for x86_64 and aarch64 architectures available via the Unbreakable Linux Network.
> New Manic Android malware can exfiltrate data through nearby devices
A new Android malware named Manic targeting users in multiple European countries has a fallback data exfiltration mechanism that uses nearby infected devices. [...]
> Oracle perl-Date-Manip Important DoS Fix ELSA-2026-56971
Oracle Linux Security Advisory ELSA-2026-56971 announces updated rpms for version 10 to address CVE-2026-60075, fixing a potential regex DoS vulnerability in date/time parsing.
> Oracle Linux glib2 Moderate D-Bus Buffer Overflow Patch ELSA-2026-57015
Oracle Linux 10 has updated glib2 packages available, addressing multiple CVEs including buffer overflows and validation issues to enhance security and system stability.
> UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations
Cisco Talos discovered a Chinese-speaking cybercrime group, tracked as UAT-10147, that targets a wide range of vulnerable web servers. This is an overview of the campaign, examining the countries affected, potential impact of BadIIS infections, the attack chain, and post-compromise tactics.
> Oracle Linux 9 pcp Important Command Injection Issues ELSA-2026-55740
Oracle Linux 9 has released security updates for the Performance Co-Pilot (PCP) package, addressing multiple vulnerabilities and adding various enhancements and options in its tools.