[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (21 articles)

|

// AI-powered summary generated at 08:01

> TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks
Cybersecurity researchers have disclosed details of a previously undocumented Python implant framework dubbed TWINLOOT. "TWINLOOT is a modular, PyArmor-hardened Python implant designed to operate its entire command-and-control infrastructure inside trusted Microsoft services," Ontinue said in a tec...
> AI "Mind Viruses" Can Spread Between Agents Through Persistent Prompt Files
Security researchers at Anthropic and Switzerland's EPFL have demonstrated that self-propagating payloads can spread from one artificial intelligence (AI) agent to the next through the editable system prompt files that autonomous agent harnesses use to carry state between sessions. The work, releas...
> Belgique : 148 251 profils exposés par un pirate
Une base belge piratée de 148 251 profils, avec IBAN et données personnelles, aurait été exposée selon un pirate sans authentification.
> Xpander Raises $7.5 Million for AI Management and Governance
Xpander’s platform uses a universal agent harness that executes AI agents as portable workloads and securely renders interfaces on demand. The post Xpander Raises $7.5 Million for AI Management and Governance appeared first on SecurityWeek.
> SpyGuard et MVT traquent les spywares mobiles
SpyGuard et MVT aident à rechercher des traces de spyware sur smartphones grâce au réseau et à l’analyse forensique.
> How to write a resignation email (with examples and templates)
Find out how to write a letter of resignation email, plus simple resignation email templates designed to simplify your offboarding process.
> Fortinet Acquires AI Security Company Virtue AI
Fortinet will use Virtue AI technology to enhance its AI security portfolio, including for AI models, applications, and agentic systems. The post Fortinet Acquires AI Security Company Virtue AI appeared first on SecurityWeek.
> Download: 2026 Credential Risk Report
85% of cybersecurity professionals consider compromised credentials a primary attack path, yet only 19% continuously monitor active credentials and automatically remediate exposure. The 2026 Credential Risk Report examines where credential security programs fall short and what it takes to move towar...
> Investigations Don’t Arrive In One Tidy Format 
From mobile extractions and emails to cloud data and video, see how Cellebrite Genesis brings diverse evidence sources together to help enterprise investigators reach faster, source-traceable and defensible findings.
> Google’s $10,000 refund test shows why AI agents need zero trust
Google’s open-source autonomous Customer Support & Returns Agent, built using the Agent Development Kit (ADK) and Gemini, demonstrates how developers can apply zero-trust security principles to AI agents that interact with sensitive systems and take real-world actions. The project tests an appro...
> 16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets
Cybersecurity researchers have flagged a new typosquatting campaign targeting RubyGems users with a Windows-based information stealer. OpenSourceMalware, which discovered the activity on August 15, 2026, is tracking the threat under the moniker StubMaker. The complete list of packages published as...
> Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478)
GitLab has released patches for two vulnerabilities, including a critical-severity code injection flaw that can be exploited without authentication. The vulnerabilities affect GitLab Community Edition (CE) and Enterprise Edition (EE) versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 befor...
> IA : il cache une injection de prompt dans un document judiciaire, le juge le sanctionne
Un plaignant a caché du texte blanc dans ses écritures pour manipuler toute IA lisant le document. Le juge lui a retiré l'accès au dépôt en ligne. Le post IA : il cache une injection de prompt dans un document judiciaire, le juge le sanctionne a été publié sur IT-Connect.
> One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025
A single piece of infrastructure has been pulling records out of Salesforce and ServiceNow customer portals across multiple industries for more than a year, according to research published this week by agent security platform Reco. The activity, which Reco has named the City Forum campaign after a...
> Cyber Incident Disrupts Student Services at UT San Antonio
UT San Antonio has taken IT systems offline following a cyber incident, disrupting student registration and tuition payments days before term is due to resume
> Be careful what you put in “anyone with the link” Google Docs
As one developer found out when his Google Doc containing company passwords showed up in Google search results.
> Microsoft tests faster Windows File Explorer, new context menu
Microsoft has started testing a faster File Explorer and a less cluttered and more customizable context menu in Windows 11 preview builds rolling out to Insiders this week. [...]
> New Malware turns Microsoft cloud into its control center
Security researchers are warning of a newly uncovered Python malware framework that routes much of its command-and-control (C2) activity through Microsoft services that defenders already expect to see. The Ontinue Cyber Defense Center discovered the implant while investigat...
> Infosec News Nuggets — August 18, 2026
Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects GitLab shipped an out-of-cycle patch for a critical flaw, tracked as CVE-2026-19478 with a CVSS score of 9.4, that could have let an unauthenticated attacker remotely modify or delete public projects and user dat...
> 300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw
Tracked as CVE-2026-15748, the arbitrary file upload bug allows unauthenticated attackers to upload executable files. The post 300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw appeared first on SecurityWeek.