[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (5 articles)

|

// AI-powered summary generated at 04:00

> CVE-2026-24301 Microsoft Copilot Information Disclosure Vulnerability
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.
> Ubuntu 26.04 LTS c3p0 Important Remote Code Exec Vulnerability USN-8642-1
Ubuntu has resolved multiple security vulnerabilities in c3p0, a JDBC connection pooling library, affecting various LTS versions, potentially allowing remote code execution and denial of service.
> NETSCOUT expands Adaptive DDoS Protection with outbound attack mitigation
NETSCOUT has announced an extension of its Adaptive DDoS Protection (ADP) solution enabling service providers to automatically detect and mitigate outbound DDoS attack traffic. By extending protection from the attack target towards its source, NETSCOUT helps operators prevent compromised subscriber...
> ResetNightmare : cette faille Kerberos permet de prendre le contrĂ´le du domaine Active Directory
Baptisée ResetNightmare (CVE-2026-27912), une faille Kerberos permet de réinitialiser le mot de passe de n'importe quel compte Active Directory. Le post ResetNightmare : cette faille Kerberos permet de prendre le contrôle du domaine Active Directory a été publié sur IT-Connect.
> Intraverse : 16,9 millions d’entrées exposées
Un casino en ligne aurait exposé 16,9 millions d’entrées, révélant joueurs, bots, portefeuilles et infrastructure Web3.
> Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect
Research by: Jaromír Hořejší (@JaromirHorejsi) Key points Introduction We first noticed a ransomware family called StopAndProtect in the middle of May 2026. Further analysis of the infrastructure reveals that the infection chain starts with a ClickFix social-engineering technique, which prompts vict...
> USN-8642-1: c3p0 vulnerabilities
It was discovered that c3p0 was vulnerable to remote code execution via maliciously crafted serialized objects and JNDI references. An attacker could use this to execute arbitrary code, bypass security restrictions, or cause a denial of service.
> Copilot tricked into telling reseachers how to hack itself
How to social engineer an AI's reasoning engine
> AI-Driven Vulnerability Surge Breaks the Traditional Patching Model
Rapid7 warns that traditional patch cycles cannot keep pace with soaring vulnerability disclosures and faster exploitation, forcing defenders to prioritize exposure over severity scores. The post AI-Driven Vulnerability Surge Breaks the Traditional Patching Model appeared first on SecurityWeek.
> TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks
Cybersecurity researchers have disclosed details of a previously undocumented Python implant framework dubbed TWINLOOT. "TWINLOOT is a modular, PyArmor-hardened Python implant designed to operate its entire command-and-control infrastructure inside trusted Microsoft services," Ontinue said in a tec...
> AI "Mind Viruses" Can Spread Between Agents Through Persistent Prompt Files
Security researchers at Anthropic and Switzerland's EPFL have demonstrated that self-propagating payloads can spread from one artificial intelligence (AI) agent to the next through the editable system prompt files that autonomous agent harnesses use to carry state between sessions. The work, releas...
> Belgique : 148 251 profils exposés par un pirate
Une base belge piratée de 148 251 profils, avec IBAN et données personnelles, aurait été exposée selon un pirate sans authentification.
> Xpander Raises $7.5 Million for AI Management and Governance
Xpander’s platform uses a universal agent harness that executes AI agents as portable workloads and securely renders interfaces on demand. The post Xpander Raises $7.5 Million for AI Management and Governance appeared first on SecurityWeek.
> SpyGuard et MVT traquent les spywares mobiles
SpyGuard et MVT aident à rechercher des traces de spyware sur smartphones grâce au réseau et à l’analyse forensique.
> How to write a resignation email (with examples and templates)
Find out how to write a letter of resignation email, plus simple resignation email templates designed to simplify your offboarding process.
> Fortinet Acquires AI Security Company Virtue AI
Fortinet will use Virtue AI technology to enhance its AI security portfolio, including for AI models, applications, and agentic systems. The post Fortinet Acquires AI Security Company Virtue AI appeared first on SecurityWeek.
> Download: 2026 Credential Risk Report
85% of cybersecurity professionals consider compromised credentials a primary attack path, yet only 19% continuously monitor active credentials and automatically remediate exposure. The 2026 Credential Risk Report examines where credential security programs fall short and what it takes to move towar...
> Investigations Don’t Arrive In One Tidy Format 
From mobile extractions and emails to cloud data and video, see how Cellebrite Genesis brings diverse evidence sources together to help enterprise investigators reach faster, source-traceable and defensible findings.
> Google’s $10,000 refund test shows why AI agents need zero trust
Google’s open-source autonomous Customer Support & Returns Agent, built using the Agent Development Kit (ADK) and Gemini, demonstrates how developers can apply zero-trust security principles to AI agents that interact with sensitive systems and take real-world actions. The project tests an appro...
> 16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets
Cybersecurity researchers have flagged a new typosquatting campaign targeting RubyGems users with a Windows-based information stealer. OpenSourceMalware, which discovered the activity on August 15, 2026, is tracking the threat under the moniker StubMaker. The complete list of packages published as...