[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (51 articles)

|

// AI-powered summary generated at 12:01

> Oracle Linux 8 bind Important CVE Security Fixes ELSA-2026-54654
Oracle Linux has released updated bind packages for version 8 addressing multiple CVEs, enhancing DNS security through various validation and rejection improvements in DNS records.
> ChainDrop worm crawls into npm supply chain, evades standard defenses
Shai-Hulud variant poisons 444 packages, spreads via tarballs and dev-tool hooks
> SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch
A maximum-severity security vulnerability impacting SAP Commerce Cloud is witnessing active exploitation efforts. The vulnerability, tracked as CVE-2026-58231, is rated 10.0 on the CVSS scoring system. It relates to an instance of insufficient authorization checks and input validation. "SAP Commer...
> macOS Screen Sharing Flaw Exploited to Deploy Monero Miners
Hackers are exploiting a macOS Screen Sharing flaw to gain root access and install Monero miners on Macs with port 5900 exposed online. The Dutch National Cyber Security Centre confirmed active exploitation of a critical macOS authentication flaw, tracked as CVE-2026-65400 (CVSS score of 9.8), less...
> Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner
A recently patched security flaw in Apple macOS has come under active exploitation in the wild to deploy a cryptocurrency miner, the Netherlands National Cyber Security Centre (NCSC) has warned. The vulnerability in question is CVE-2026-65400 (CVSS score: 9.8), a critical authentication issue impac...
> GeoServer Zero-Day Is Already Being Probed. That’s the Problem
GeoServer faces an unpatched zero-day enabling SQL injection and potentially RCE, with attackers already probing exposed systems. A newly disclosed GeoServer zero-day is already attracting active exploitation attempts, and there is no patch available yet. Organisations running the open-source geospa...
> The Illusion of a Lock – How AI is changing the speed and scale of hands-on WordPress vulnerability research.
2026: the year the tools learned to hack In May 2026, OpenAI began testing an internal research model against a cybersecurity benchmark called ExploitGym. While the test environment was not supposed to have access to the open internet, there was, however, one narrow path out because the agents still...
> OSINT Tools Update
OSINT Tools Update
> New Firewall Guide
New Firewall Guide
> Tecnoabi
Une entreprise prestataire de la Consejería de Agricultura, nommée Tecnoabi, a été victime d'une cyberattaque qui a exposé les données personnelles (identifiants, contacts et bancaires) de milliers d'agriculteurs et de propriétaires de terres bénéficiaires des aides de la Politique Agricole Commune...
> The New Blog
The New Blog
> Cartrack
L'Information Regulator enquête sur une violation de données chez Cartrack, une société de suivi de véhicules. L'incident, qui est survenu en août, a été un incident de ransomware. Cartrack a confirmé que sa base de données client a été accédée, contenant des informations personnelles telles que les...
> Novocure
L'entreprise d'oncologie Novocure a signalé un incident de sécurité cibernétique qui a exposé les dossiers internes de plus de 1 400 patients américains. L'accès non autorisé aux systèmes d'information a eu lieu à la mi-août.
> The New Blog
The New Blog
> Administration de l'État de Berlin
Le réseau de l'État de Berlin a été victime d'une cyberattaque. Deux administrations sénatoriales, celles de l'Aménagement du territoire et de la Mobilité, ont été isolées du réseau après la découverte d'une intrusion. L'attaque, attribuée à une vulnérabilité dans le système de l'administration de l...
> Lincoln
Le bureau de la ville de Lincoln a été contraint de fermer suite à une cyberattaque qui a chiffré une partie de son réseau. Les autorités locales travaillent à la restauration des systèmes pour éviter toute réinfection et minimiser les perturbations des services.
> Chromium: CVE-2026-19556 Use after free in V8
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
> Chromium: CVE-2026-19557 Use after free in TabStrip
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
> How Anthropic plans to watermark Claude's AI-generated text
It could soon become easier to identify AI-generated content, even if it's not the usual "It's Not X, it's Y" type of post you'd come across on LinkedIn and other socials. [...]
> Chromium: CVE-2026-19558 Use after free in Extensions
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.