[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (5 articles)

|

// AI-powered summary generated at 04:00

> Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps
Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal that it said could allow a single click on a crafted link to silently pull data from connected apps and other information available to the victim's Copilot session. The flaws, which the researchers collectively na...
> Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets
Two critical vulnerabilities impacting MLflow, an open-source artificial intelligence (AI) platform, and FUXA, an open-source, web-based SCADA / HMI software built for operational technology (OT) and industrial automation, are witnessing malicious scanning and exploitation efforts. According to ind...
> Clop created custom web shell for Windchill data theft attacks
A custom Java web shell likely linked to the Clop ransomware gang was designed specifically for PTC Windchill and FlexPLM servers, with built-in features to decrypt credentials, enumerate file repositories, and steal files. [...]
> Medusa ransomware tallies hundreds of new victims, says updated advisory on group’s tactics
The updated warning from the FBI, CISA and HHS draws on a year’s worth of investigations to detail how the group gains initial access and what it does afterward. The post Medusa ransomware tallies hundreds of new victims, says updated advisory on group’s tactics appeared first on CyberScoop.
> Hunting MacSync Stealer infrastructure through behavioral pivots
MacSync Stealer rapidly rotates domains to evade detection, but its behavior remains consistent. Learn how Microsoft uncovered 30+ related domains using durable hunting pivots. The post Hunting MacSync Stealer infrastructure through behavioral pivots appeared first on Microsoft Security Blog.
> Project noRecognition: Teaching AI to Fool Surveillance Cameras
Researchers tested 31 million patterns to disrupt surveillance AI, with promising results but significant gaps between simulation and real-world use. The Kansas City-based cybersecurity researcher Bill Swearingen spent the past year doing something that sounds almost too simple to work: printing pat...
> Security Hub Extended adds Supply Chain Security as its tenth category
Since February, we’ve grown AWS Security Hub Extended from 14 curated partners across 9 categories to 23 partners across 10. At Black Hat this month, 14 of those partners were at the Amazon Web Services (AWS) booth demoing live. Four of those partners delivered theater talks and ten were featured on...
> Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000
A ransomware affiliate calling itself Ransom Busters has been spotted proactively sending emails to victim organizations and claims to delete stolen data from ransomware groups' servers in exchange for a fee ranging from $20,000 to $60,000. "In these messages, the third-party offers to help the vic...
> Oracle Linux 8 Node.js Important Security Update ELSA-2026-54530
Oracle Linux has released updated RPMs for Node.js and related packages addressing multiple vulnerabilities across its versions for x86_64 and aarch64 architectures, enhancing overall security.
> Oracle Linux 8 ELSA-2026-55530 389-ds Important DoS Buffer Overflow
Oracle published multiple RPM updates for Oracle Linux 8 addressing various CVEs, primarily related to security vulnerabilities in the 389-ds-base package, enhancing overall system security.
> Berlin cuts two state ministries off government network after security breach
The affected ministries — one responsible for urban development, construction and housing, and the other for mobility, transport, climate protection and the environment — have been isolated from government networks since Friday as a precaution.
> Oracle Linux 8 Unbound Important Fix for CVE-2026-44690 ELSA-2026-55784
Oracle Linux 8 has released updated RPMs addressing CVE-2026-44690, including various unbound packages for x86_64 and aarch64 architectures, alongside related source RPM information.
> Oracle Linux 8 haproxy Important NULL Pointer Threat ELSA-2026-55859
Oracle Linux 8 has released new haproxy updates addressing a NULL pointer dereference vulnerability (CVE-2026-55204) with specific RPM formats available for x86_64 and aarch64 architectures.
> Comcast adds motion sensing to millions of its newer routers, with a privacy catch
A new feature added to Comcast's newest routers can detect if there is motion is inside your home without needing traditional motion sensors.
> Oracle Linux 10 ELSA-2026-55892 Unbound Important Buffer Overflow Threat
Oracle Linux has released updated RPMs for version 10 to address two critical vulnerabilities and enhance security through unit tests. These updates are available for x86_64 and aarch64 architectures.
> University of Texas forced to take systems offline in San Antonio after cyberattack
The University of Texas at San Antonio, which serves 40,000 students across six campuses, said its IT team identified threat activity on its academic campus over the weekend and took some systems, including phones, offline in response.
> UODO - autorité polonaise
Le Défenseur des droits civiques polonais (RPO) a rejoint une procédure devant la Cour administrative suprême pour soutenir la position du Président de l'Office de protection des données personnelles (UODO) concernant la divulgation de données personnelles par le Parquet national lors d'une conféren...
> AEPD - autorité espagnole
Un club sportif a été averti par l'autorité espagnole pour avoir ajouté une personne à un groupe de messagerie instantanée sans son consentement, l'autorité ayant jugé que l'utilisation du groupe à des fins organisationnelles rendait le club responsable du traitement, malgré ses dénégations.Faits et...
> Bluesky says its recent outage was caused by another DDoS attack
This is the latest large-scale DDoS attack to hit the social networking site this year.
> CNIL
La Commission Nationale de l'Informatique et des Libertés (CNIL) a été notifiée d'une violation de données affectant le système d'information de la Direction générale des Finances publiques (DGFiP).Le 14 août 2026, le ministère de l'Économie et des Finances a révélé qu'une violation de données avait...