> TODAY'S SUMMARY (51 articles)
Today's cybersecurity landscape reveals a record surge in ransomware attacks, with 1,073 firms targeted globally in August, primarily in the industrial sector. Microsoft has disrupted the AI-powered phishing service, EvilTokens, which compromised over 12,000 inboxes across various organizations. Meanwhile, critical vulnerabilities have been reported in several platforms, including Adobe, WordPress, and F5's BIG-IP, necessitating immediate patches to prevent potential exploitation. Additionally, the ShinyHunters group claims to have breached FBI systems via a zero-day vulnerability in Oracle PeopleSoft, threatening to leak sensitive data. In malware developments, Chinese hackers are leveraging a Chrome-Windows zero-day to deploy CLEANGULP malware, highlighting the ongoing threat posed by exploit chains.
|
// AI-powered summary generated at 12:01
De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance et une élévation de privilèges.
Ce bulletin d'actualité du CERT-FR revient sur les vulnérabilités significatives de la semaine passée pour souligner leurs criticités. Il ne remplace pas l'analyse de l'ensemble des avis et alertes publiés par le CERT-FR dans le cadre d'une analyse de risques pour prioriser l'application des...
WooCommerce 1.5.0 - Unauthenticated Arbitrary File Upload
D-Link DNS_340L - OS Command Injection
Outdated protocols, forgotten configurations, and legacy dependencies continue to create opportunities for attackers in modern environments. This research explores how NetNTLMv1 can still be leveraged today and how improvements in attack tooling are reducing the cost and complexity of exploiting it.
ipTIME A3004T - Remote Code Execution
Joomla JCE_2.9.15 - Remote Code Execution
Cryptocurrency hardware wallet provider SafePal is warning of a data breach affecting about 39,798 customers after a flaw was exploited to steal customer order information, and a threat actor is now claiming to be selling the stolen data. [...]
Duplicati 2.2.0.3 - JWT Signing Key Leak
Nmap 7.99 - Extension Header Integer Underflow
Large DDoS attacks disrupted Threema, causing severe communication outages. Threema On-Prem users were unaffected by the attacks. Threema suffered multiple large-scale DDoS attacks that disrupted its secure messaging service and caused severe communication issues. Organizations using Threema On-Prem...
phpSysInfo 3.4.5 - IP Allowlist Bypass
webpack_devserver 5.2.5 - CSRF
Claude is experiencing a major outage, with users reporting login problems and degraded performance across several Anthropic services. [...]
Probo 0.222.2 - IDOR
flyto_core 2.26.7 - Server-Side Request Forgery
Wireshark release 4.6.8 fixes 28 vulnerabilities and 25 bugs.
NanaZip 6.5 - DoS
Debian released an advisory for vulnerabilities in Neutron, the OpenStack virtual network service, urging users to upgrade to version 2:26.0.3-0+deb13u3 for better API permission validation.
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Kimsuky Integrates AI into Attack Operations, From AI-Generated Decoy Documents to a Local LLM ShieldBreak – August 2026 disclosure  Kimwolf v7: A...