[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> Multiples vulnérabilités dans les produits Splunk (20 août 2026)
De multiples vulnérabilités ont été découvertes dans les produits Splunk. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et une atteinte à la confidentialité des données.
> Multiples vulnérabilités dans Microsoft Windows (20 août 2026)
De multiples vulnérabilités ont été découvertes dans Microsoft Windows. Elles permettent à un attaquant de provoquer une élévation de privilèges et une atteinte à la confidentialité des données.
> Free PDF Self-Publishing Guide
Free PDF Self-Publishing Guide
> Multiples vulnérabilités dans Ceph (20 août 2026)
De multiples vulnérabilités ont été découvertes dans Ceph. Elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à la confidentialité des données et un contournement de la politique de sécurité.
> Multiples vulnérabilités dans les produits Cisco (20 août 2026)
De multiples vulnérabilités ont été découvertes dans les produits Cisco. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et une atteinte à la confidentialité des données.
> N4D Mesh Controller: New infrastructure, a UPX-packed agent labeled "go-titan," and how to hunt for it
Datadog Security Research executed a newer N4D Mesh Controller sample in isolated microVMs, uncovering rotated infrastructure, a UPX-packed go-titan agent, MCP tool abuse in action, and direct runtime evidence of multi-service scanning and persistence.
> Multiples vulnérabilités dans les produits Citrix (20 août 2026)
De multiples vulnérabilités ont été découvertes dans les produits Citrix. Elles permettent à un attaquant de provoquer un déni de service à distance, un contournement de la politique de sécurité et un problème de sécurité non spécifié par l'éditeur.
> Smashing Security podcast #481: Never say this to a robot dog
At Black Hat this month, a group of security researchers took a $9,000 robot dog, plugged Google's AI into its brain, and jailbroke it by telling it - with a completely straight face - that it was a Pokemon. What followed involved a wall, a blue ice chest, and anyone in the room wearing white shoes....
> 'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllers
'It is an active threat'
> Some Tech Companies Have Privately Pushed Back on ICE Subpoenas. They Should All Do More.
In a handful of known cases, large social media companies have privately pushed back against Immigration and Customs Enforcement (ICE) subpoenas when the agency tried to unmask anonymous users who tracked immigration activities or criticized the government. As ICE engages in a pattern of illegal and...
> Debian Highlights Key DNS Hijacking Denial of Service CVEs 6452-1
Debian issued an advisory for Designate, revealing two vulnerabilities that may allow tenant zone manipulation, leading to denial of service or DNS hijacking. Users should upgrade packages.
> Rogue ransomware affiliate poses as recovery firm to steal payments
A suspected ransomware affiliate is posing as a ransomware recovery service called "Ransom Busters," contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fee. [...]
> Rogue ransomware affiliate poses as data recovery firm to steal payments
A suspected ransomware affiliate is posing as a ransomware recovery service called "Ransom Busters," contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fee. [...]
> Ubuntu nginx USN-8563-4 Regression Denial of Service Advisory
An update for nginx in Ubuntu addresses a regression caused by a previous security fix, reverting the change until further investigation on vulnerabilities is completed.
> Sakura Internet hack exposes data of up to 1.36 million accounts
Japanese cloud and data center service provider Sakura Internet disclosed that hackers accessed its sales management system, where customer contract and membership information is stored. [...]
> Healthtech firm CareCloud data breach impacts 3.7 million patients
U.S. healthcare IT company CareCloud disclosed that the data breach incident it suffered earlier this year has impacted more than 3.7 million individuals. [...]
> What Is a Website Attack Surface? A Beginner’s Guide to Reducing Risk
Each feature that you add to a website results in a new element that has to be managed. The credentials are accepted by a login page, the data by a contact form, new code is introduced by a plugin, and an API is used to connect your website to another service. It is also possible that an old staging...
> USN-8563-4: nginx regression
USN-8563-3 fixed a vulnerability in nginx. The fix introduced a regression in certain environments. This update reverts the fix for CVE-2026-42533 pending further investigation. We apologize for the inconvenience. Original advisory details: It was discovered that nginx incorrectly handled certai...
> Ubuntu curl Important Sensitive Data Exposure USN-8651-1 CVE-2026-11856
Ubuntu Security Notice USN-8651-1 warns of a curl vulnerability affecting multiple Ubuntu releases, allowing sensitive information exposure. Users should update their systems to the latest package versions.
> Ubuntu libpng Critical DoS Threats Addressed USN-8639-1
Ubuntu Security Notice USN-8639-1 addresses multiple vulnerabilities in libpng affecting various releases, potentially allowing denial of service or arbitrary code execution.