[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (21 articles)

|

// AI-powered summary generated at 08:01

> Details emerge on BlackFile’s recent attacks on financial companies
BlackFile’s four affiliate groups are still targeting victims, including medical technology organizations. Several potential victims received new extortion demands last week, according to Google. The post Details emerge on BlackFile’s recent attacks on financial companies appeared first on CyberScoo...
> Irregular says ‘human oversight’ responsible for AI sandbox escape incidents
In a post-mortem, the frontier AI testing company said internet access for models is necessary to fully test out their cybersecurity capabilities. The post Irregular says ‘human oversight’ responsible for AI sandbox escape incidents appeared first on CyberScoop.
> Apple Patches iOS and macOS, (Mon, Aug 17th)
Apple today released updates for iOS/iPadOS (26 and 18) and macOS 26. This update fixes 108 vulnerabilities and comes about two weeks after the much smaller macOS update that addressed the single screen-sharing vulnerability. This vulnerability did not affect iOS/iPadOS.
> ‘Unprecedented’ number of Apple users received recent spyware alert, say investigators
Cybersecurity experts who investigate spyware attacks say the number of people who received a recent threat notification from Apple is unusually high.
> Nearly 750k had financial info, SSNs leaked in South Carolina loan company breach
The breach affected anyone who received a loan through the company or inquired about a loan product through a third party.
> Hacker claims 3.6 million Azure account records stolen from major companies
A threat actor is selling employee databases allegedly stolen from the Microsoft Azure infrastructure of multiple Fortune 500 companies after gaining access using compromised credentials. [...]
> Pokémon Center data breach exposes customer info, cancels some orders
Pokémon Center is notifying customers in the United Kingdom and Germany that it suffered a third-party data breach after hackers stole customer personal and order information from third-party logistics provider CEVA Logistics. [...]
> Debian Ironic High Sign-in Access Bypass Code Execution DSA-6445-1
Debian released Advisory DSA-6445-1 highlighting multiple vulnerabilities in Ironic that could lead to bypassing access restrictions, information leaks, or arbitrary code execution, advising users to upgrade.
> Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection
Cybersecurity researchers at Wiz have disclosed a new GitHub Actions workflow injection vulnerability in Snowflake's public snowflakedb/snowflake-connector-net repository that it said could be exploited through a crafted GitHub issue to execute commands in a workflow containing internal Jira credent...
> Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads
A critical security flaw has been disclosed in Forminator Forms, a WordPress plugin with more than 600,000 active installations, that could be exploited to achieve arbitrary code execution on susceptible sites. The vulnerability, tracked as CVE-2026-15748, is rated 9.8 out of 10.0 on the CVSS scori...
> Ubuntu Engrampa Important Code Execution Risk USN-8640-1 CVE-2023-52138
A vulnerability in Engrampa could allow attackers to execute arbitrary code via malicious files. Users on affected Ubuntu versions should update to the latest package versions for security.
> SafePal Says 39,798 Customers Hit by Data Breach
SafePal says a breach exposed personal data of 39,798 customers, but not wallet credentials, private keys, seed phrases, or payment information. SafePal disclosed a data breach affecting about 39,798 customers after hackers exploited a vulnerability in its order-tracking plugin. The flaw exposed inf...
> Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic
Cybersecurity researchers have traced the continued evolution of the Cavern (aka Cav3rn) command-and-control (C2) framework used by Iranian nation-state hackers in attacks targeting entities in Israel. Russian cybersecurity company Kaspersky said its ongoing monitoring of the threat activity cluste...
> USN-8640-1: Engrampa vulnerability
It was discovered that Engrampa incorrectly handled symbolic links when extracting certain archives. An attacker could possibly use this issue to write arbitrary files and execute arbitrary code.
> Updates to your AWS Sign-In experience
Amazon Web Services (AWS) is gradually introducing updates to the AWS Sign-In and sign-up experience to a limited number of customers. We’re sharing these changes so you will know what to expect as we gradually make the updated experience available to more customers. These updates include new option...
> LiteLLM Supply-Chain Attack – Technology, Banking and Healthcare the Most Affected
The SANDCLOCK LiteLLM supply-chain attack exposed credentials across 2,038 repositories, affecting technology, finance, healthcare, retail and more. Resecurity (USA) estimated the most affected sectors by the “SANDCLOCK” backdoor, which was planted as a result of the code repository compromise. Acco...
> 600,000 WordPress Sites Affected by Arbitrary File Upload Vulnerability in Forminator Forms WordPress Plugin
On July 14th, 2026, we received a submission for an Unauthenticated Arbitrary File Upload vulnerability in Forminator Forms, a WordPress plugin with more than 600,000 active installations. The post 600,000 WordPress Sites Affected by Arbitrary File Upload Vulnerability in Forminator Forms WordPress...
> EDPS
Le ContrÎleur européen de la protection des données (CEPD) a communiqué sur ses récentes activités concernant la surveillance des décisions automatisées, l'identité numérique et la coopération internationale en matiÚre de protection des données.Le CEPD a mis à disposition une nouvelle liste de contr...
> SDTB - autorité allemande
La Déléguée à la protection des données et à la transparence de Saxe a signalé une augmentation des notifications de violations de données en juillet et août, due à l'exploitation de failles de sécurité dans des systÚmes de gestion de contenu.Cette hausse concerne des instances d'hébergement web pir...
> SafePal latest crypto hardware wallet maker affected by breach, with nearly 40,000 impacted
The crypto hardware wallet company SafePal confirmed a data breach on Sunday, telling users that nearly 40,000 customers had information stolen during a recent security incident.