[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (21 articles)

|

// AI-powered summary generated at 08:01

> Fortinet expands AI security portfolio with Virtue AI acquisition
Fortinet has acquired Virtue AI, strengthening its broader Security for AI strategy and its vision for securing the agentic enterprise. The acquisition builds on Fortinet’s existing AI security portfolio, which includes the FortiGate Hyperscale Firewall. As organizations deploy AI applications and a...
> Proton VPN migre vers Rust : un nouveau cœur WireGuard pour ses applications
Proton a dévoilé un nouveau socle logiciel écrit en Rust pour remplacer wireguard-go dans ses applications VPN, ainsi que muon pour lutter contre la censure. Le post Proton VPN migre vers Rust : un nouveau cœur WireGuard pour ses applications a été publié sur IT-Connect.
> 17th August – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 17th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Colombia’s Ministry of Justice has experienced a ransomware attack that affected part of its technology infrastructure and disrupted public services re...
> ShieldBreak bypasses Microsoft’s patch for earlier Defender flaw
The researcher who found RoguePlanet has discovered ShieldBreak, a new way to bypass Microsoft’s fix and gain SYSTEM privileges.
> WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover
Critical User Profile Builder flaw let unauthenticated attackers access administrator accounts
> ⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More
The expensive attacks are not always the clever ones. This week had plenty of proof. Exposed services got hit, old bugs found fresh use, browser sessions became attack paths, and supply-chain problems kept spreading farther than the original compromise. A lot of it came down to access that was alre...
> Microsoft Entra Cloud Sync : la synchronisation des appareils est disponible en préversion
Microsoft a ajouté une fonctionnalité à Entra Cloud Sync : la synchronisation des objets ordinateur de l'Active Directory vers Entra ID, appelée Device Sync. Le post Microsoft Entra Cloud Sync : la synchronisation des appareils est disponible en préversion a été publié sur IT-Connect.
> Crypto hardware wallet owners face fresh security risks after recent spate of personal data thefts
The hacks at shipping companies used to mail out hardware wallets puts crypto owners at greater risk of real-world attacks.
> Windows Server 2022 reaches end of mainstream support in 60 days
Microsoft has reminded IT administrators that Windows Server 2022 is rapidly approaching its mainstream end date of October 2026, when it will switch to extended support. [...]
> Ukraine says cyberattack hit Russian e-commerce giant Wildberries amid drone strikes
Ukraine’s military intelligence claimed it disrupted the operations of Russia’s largest online marketplace, Wildberries, in a cyberattack intended to amplify the impact of drone strikes on the company’s infrastructure.
> Synology dévoile la gamme neo+ : quatre NAS moins chers, mais sans mémoire ECC
Synology dévoile les DS1825neo+, DS1525neo+, DS925neo+ et DS725neo+ : même plateforme que les DS Plus, mais 4 Go de DDR4 non-ECC. Disponibilité en octobre. Le post Synology dévoile la gamme neo+ : quatre NAS moins chers, mais sans mémoire ECC a été publié sur IT-Connect.
> Attackers exploit patched macOS Screen Sharing flaw to deploy cryptominer
A recently patched security flaw in Apple macOS is being actively exploited by hackers to bypass authentication, gain root access, and install a cryptominer, the Netherlands’ National Cyber Security Centre (NCSC) warns. The vulnerability, tracked as CVE-2026-65400, , let attackers authenticate to ma...
> Zhipu says new coding AI developed advanced cyber skills faster than expected
Chinese AI developer Zhipu has launched GLM-5.3, a new coding-focused AI model that the company says has developed unexpectedly strong cybersecurity capabilities, putting it close to global leading models in vulnerability discovery while remaining behind them on deeper exploit...
> Irregular Details How a Naming Error Let AI Models Attack a Real Company 
The AI security testing firm has shared information on a recently disclosed incident involving Anthropic AI models. The post Irregular Details How a Naming Error Let AI Models Attack a Real Company  appeared first on SecurityWeek.
> How MCP Servers Can Expose Enterprise Secrets
MCP servers can expose enterprise secrets through plaintext configuration files, over-permissioned access and prompt injection, often before security teams even know the server is running. As more organizations adopt AI agents into their systems, that exposure can silently become a major gap in MCP...
> AI Image Classification For Forensics – Build Custom Detectors In Seconds | BelkaGPT
See how BelkaGPT turns image forensics from “scroll and squint” into “describe and detect” with offline AI image descriptions and instant custom classifiers – no training datasets required.
> Crook hawks millions of records allegedly plundered from corporate Azure tenants
McDonald's, Vodafone, TCS, Kyndryl, and others named as researchers point to compromised credentials
> New macOS malware turns stolen browsers into attacker-controlled sessions
Mac users are being freshly warned of suspicious websites asking them to open Terminal and install software. Jamf Threat Labs has uncovered a multi-stage macOS infostealer, dubbed AmnesiaStealer, that uses a ClickFix-style fake GitHub download page to trick victims into execut...
> Philips and GE investigating Clop ransomware data theft claims
Tech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data. [...]
> Hacking Public Wi-Fi DNS to Steal Credentials
Criminals are hacking into public Wi-Fi devices—at hotels, conference centers, and so on—around the world and changing their DNS settings. The goal is to redirect users to fake login pages and steal their credentials.