Oracle Linux 10 has received an update with various kernel RPMs addressing multiple CVEs, enhancing security and adding new certificates, along with numerous bug fixes across different subsystems.
Oracle Linux 10 has received updated RPMs for curl due to several vulnerabilities, including fixes for proxy issues, OAuth2 token leakage, and connection reuse problems, addressing numerous CVEs.
A new Android malware named Manic targeting users in multiple European countries has a fallback data exfiltration mechanism that uses nearby infected devices. [...]
Oracle Linux 10 has released updates for the yggdrasil package, fixing CVE-2026-33810 and rebuilding it against an updated golang. New RPMs are available for x86_64 and aarch64.
Cisco Talos discovered a Chinese-speaking cybercrime group, tracked as UAT-10147, that targets a wide range of vulnerable web servers. This is an overview of the campaign, examining the countries affected, potential impact of BadIIS infections, the attack chain, and post-compromise tactics.
The newly identified SPECTRE implant represents an evolution in commodity intrusion tooling, integrating cross-platform C2 operations, process injection, credential theft, anti-analysis protections, and kernel-level endpoint detection and response (EDR) bypass functionality.Â
Unit 42 details how attackers exploit enterprise collaboration tools for identity phishing and credential theft. Discover key defense strategies.
The post Identity Abuse Through Trusted Communication Channels appeared first on Unit 42.
Zimperium lifts the lid on the ToxicPanda 2.0 Android banking Trojan
Cellebrite Genesis is expanding globally and is now generally available to enterprises, helping teams surface critical connections in minutes rather than weeks.
A usage policy for Flock license plate reader cameras tells police not to talk about the cameras:
When cops use Flock to arrest someone in Wapello County, Iowa, they don’t want them to know. A usage policy for the automated license plate reader cameras in the county tells police, in no uncertain ter...
CERT Polska, the Polish Computer Emergency Response Team (CERT), warned that attackers have begun exploiting a critical vulnerability in Zimbra Collaboration Suite (ZCS). [...]
Microsoft explique comment lire les colonnes NPU et GPU du Gestionnaire des tâches pour savoir si vos applications exploitent le matériel IA de la machine.
Le post Votre PC utilise-t-il vraiment son NPU ? Windows 11 peut vous le dire a été publié sur IT-Connect.
Huntress researcher explains how they were targeted by an elaborate and persistent phishing scam following Def Con
OpenAI is previewing Private Safety Processing with early customers seeking greater certainty about how their data will be protected as AI systems become more capable. The system identifies patterns across related interactions while restricting OpenAI personnel from accessing the underlying content....
Threat actors are using AI to write exploit scripts targeting internet-exposed Siemens S7 Series programmable logic controllers (PLCs) used across water, energy, manufacturing, and other critical infrastructure sectors, according to US federal agencies. PLCs are the small industrial computers that o...
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds an MLflow vulnerability to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA)Â added a Progress LoadMaster vulnerability, tracked as CVE-2026-64849 (CVSS score of 9.3), to its...
A set of 40 Mozilla Firefox extensions has been found to engage in cryptocurrency wallet theft by masquerading as OKX, Rabby Wallet, TronLink, and other Web3 products.
According to the Socket Threat Research team, the extensions are part of a broader set of 77 browser add-ons that share source code...
The US charged 17 Iranians over a years-long hacking campaign that stole 31TB from universities, companies and government agencies worldwide. Eight years after the original indictment first went public, US prosecutors just added eight more names to the list. The Justice Department unsealed a superse...
Remote, unauthenticated attackers could exploit the critical-severity flaw without user interaction.
The post Exploitation Expected for Critical Authentication Bypass Patched in Citrix NetScaler appeared first on SecurityWeek.
CVE-2026-19478 can be exploited without authentication to modify or delete public projects and user data.
The post Critical GitLab Flaw Exploited Shortly After Disclosure appeared first on SecurityWeek.