[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (5 articles)

|

// AI-powered summary generated at 04:00

> Exclusive: Linux Foundation's Akrites to Go Live in September
The Linux Foundation's Akrites initiative will become operational in September, when it will begin accepting AI-powered vulnerability reports for open-source projects
> Sideloading on Android: What it is, why it’s risky, and how to do it more safely
With the new Advanced Flow for sideloading being rolled out, it's time to discuss what sideloading is and how to do it more safely.
> Unmasked: Throughput Is Not Prioritisation
When every file is treated as equally urgent, critical intelligence can get lost in the backlog. See how S21 VisionX helps investigators prioritise what matters most.
> MaaS Campaign Combines ClickFix, ErrTraffic and Cruciferra
eSentire uncovered a malware campaign combining ClickFix lures with ErrTraffic and Cruciferra
> Votre analyse Defender s’arrêtait à 80 % sur Windows ? Microsoft a corrigé ce bug !
Depuis le 18 août 2026, Microsoft Defender plantait en fin d'analyse sur Windows 10 et 11. Microsoft a confirmé le bug et l'a corrigé via une mise à jour. Le post Votre analyse Defender s’arrêtait à 80 % sur Windows ? Microsoft a corrigé ce bug ! a été publié sur IT-Connect.
> The long tail of Clop’s PTC hack is just beginning to emerge
The data theft extortion group likely compromised a critical vulnerability affecting PTC’s product lifecycle management software in June, a month before it sent threatening emails to victims. The post The long tail of Clop’s PTC hack is just beginning to emerge appeared first on CyberScoop.
> Simple Scans for Cloud Metadata Service, (Wed, Aug 19th)
Cloud providers typically expose a REST API at 169.254.169.254 that allows code running on virtual machines to retrieve machine-specific data. Some of the data is more or less harmless, such as the region the machine is running in or its MAC and IP addresses. However, the service may also be used to...
> Thunderbird 154 active Microsoft Graph pour les comptes Microsoft 365
Thunderbird 154 active la prise en charge de Microsoft Graph pour les comptes Microsoft 365, à six semaines du blocage d'EWS. Le point sur les nouveautés. Le post Thunderbird 154 active Microsoft Graph pour les comptes Microsoft 365 a été publié sur IT-Connect.
> CVE-2024-43481 Power BI Report Server Spoofing Vulnerability
Corrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only.
> CVE-2024-43612 Power BI Report Server Spoofing Vulnerability
Corrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only.
> Password spraying attacks surge 155x as hackers exploit MFA gaps
Huntress observed a 155x increase in password spraying attacks in H1 2026, including a campaign that generated more than 81 million login attempts in two weeks. The attacks exploited legacy authentication and gaps in MFA policies that left some login flows unprotected. [...]
> CVE-2023-21806 Power BI Report Server Spoofing Vulnerability
Corrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only.
> CVE-2021-41372 Power BI Report Server Spoofing Vulnerability
Corrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only.
> Grandoreiro Resurfaces in Mexico With New DLL Sideloading Campaign
Grandoreiro is active after its 2024 disruption, with Mexico now accounting for 40% of detections
> CVE-2021-26859 Microsoft Power BI Information Disclosure Vulnerability
Corrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only.
> CVE-2020-1173 Microsoft Power BI Report Server Spoofing Vulnerability
Corrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only.
> Intezer adds native response automation without separate SOAR
Intezer has announced Workflows, a native automation and response builder that enables security teams to create and customize response workflows directly inside the Intezer platform. Workflows brings response into the same platform where alerts are triaged and investigated, allowing organizations to...
> Digital Forensics Round-Up, August 19 2026
Read the latest DFIR news – UK police investigator well-being, cloud search warrant strategy, Timestamped for macOS, iLEAPP and ALEAPP updates, and more.
> Latvian officials resign after cyberattack exposes data on 1.2 million people
Latvia’s road traffic agency confirmed that hackers stole data connected to about two-thirds of the country’s population in a major cyberattack that has prompted calls for senior officials to resign.
> Virtual Event Today: CodeSecCon – Secure Your Code and Applications
CodeSecCon is the premier virtual event bringing together developers and cybersecurity professionals to revolutionize the way applications are built, secured, and maintained. The post Virtual Event Today: CodeSecCon – Secure Your Code and Applications appeared first on SecurityWeek.