[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (51 articles)

|

// AI-powered summary generated at 12:01

> US courts will start publishing how often the government uses spyware
The Administrative Office of the U.S. Courts told TechCrunch that it will start disclosing how many times judges authorized the use of spyware to wiretap suspected criminals.
> France investigates tax authority breach after hacker claims 600,000 victims
French authorities confirmed that someone gained unauthorized access to systems at the Directorate General of Public Finances in late June after stealing or misusing someone’s identity.
> Oracle’s new database security tool is free — for six months
Oracle has released a security tool intended to provide organizations with a centralized view of security risk across their database environments. Oracle Database Security Central will be available free of charge until the end of February 2027. It arrives at a critical t...
> How Cloudflare detects MCP traffic and helps secure it
Cloudflare Gateway identifies MCP requests using protocol-level heuristics. Security teams can use that signal to find shadow MCP traffic, enforce Portal-only access for approved servers, and block direct connections on managed network paths.
> Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth
The threat actor known as HoneyMyte (aka Mustang Panda) has been observed deploying an updated version of the CoolClient backdoor with a signed Windows kernel-mode rootkit that can hide and protect malicious processes, files, registry objects, and command-and-control (C2) network information. Russi...
> Oracle Linux 10 .NET 8.0 Important Bug Fix Advisory ELSA-2026-54541
Oracle Linux 10 released updated rpms for the .NET SDK and runtime, addressing specific CVEs and adding support for the platform, improving security and functionality.
> Oracle Linux 10 ELSA-2026-54590 .NET 9.0 Important Bug Fix
Oracle Linux 10 has new RPM packages for .NET SDK and Runtime, including updates for x86_64 and aarch64 architectures, addressing several CVEs and adding support for Oracle Linux.
> Autonomous AI attacks pose 'clear and present danger' to critical infrastructure
Weaponized agents could turn digital intrusions into kinetic disasters, experts warn
> Oracle 10 nghttp2 Medium HTTP Smuggling Fix ELSA-2026-54650
Oracle Linux updated packages for version 10 address CVE-2026-58055, fixing HTTP request/response smuggling and response-queue poisoning vulnerabilities, available for x86_64 and aarch64 architectures.
> Oracle Linux 9 nghttp2 Moderate HTTP Request Smuggling ELSA-2026-54662
Oracle Linux 9 has released updated rpms for libnghttp2 to address CVE-2026-58055, fixing HTTP request smuggling and response-queue poisoning vulnerabilities.
> Secure all your internal vibe-coded applications — in one click
Introducing Cloudflare Access for Workers. Attach an Access policy directly to a Worker and it applies everywhere that Worker runs — routes, custom domains, workers.dev, and previews — automatically.
> Oracle Linux gnome-remote-desktop Advisory ELSA-2026-54512 CVE-2026-18358
Oracle Linux Security Advisory ELSA-2026-54512 announces the update of gnome-remote-desktop for Oracle Linux 10, addressing CVE-2026-18358 by backporting connection throttling.
> New Mirai-Based Linux Botnet ‘Evooo1Bot’ Turns Victims Into Proxies
Evooo1Bot is a newly observed botnet based on the Mirai framework but equipped with advanced features, turning edge devices into persistent proxies
> Apple now uses iPhone alerts for targets of mercenary spyware
Apple explains how Threat Notifications help protect iPhone users targeted by mercenary spyware.
> WhatsApp is testing a new warning for scam messages
An optional new feature uses on-device AI to flag messages that look like scams.
> In Other News: Rapid7 Layoffs, Hacking a Boeing 737, Refrigeration System Vulnerabilities
Noteworthy stories that might have slipped under the radar: government AI platform deal sparks outrage, North Korean IT worker breaches federal agency, DEF CON attendee blamed for Delta flight disruption. The post In Other News: Rapid7 Layoffs, Hacking a Boeing 737, Refrigeration System Vulnerabilit...
> Shell investigates 'potential incident' after Clop data theft claims
Oil giant Shell has confirmed it is investigating a potential security incident after the Clop ransomware gang claimed it stole 89GB of data. [...]
> Cyberharcèlement : la Belgique prépare un bannissement numérique
La Belgique prépare un bannissement numérique contre le cyberharcèlement, avec identification judiciaire et contrôle des comptes.
> Trivy, Not LiteLLM Behind the 2,500 Org Compromise
Over 95% of the affected companies were exposed before the malicious LiteLLM packages were published. The post Trivy, Not LiteLLM Behind the 2,500 Org Compromise appeared first on SecurityWeek.
> Who’s Tracking You? Use This New Service to Find Out
It can be daunting to determine who's responsible for showing ads on the websites we visit, or who's harvesting data from the mobile apps we use every day. That information is already semi-public, but it is not easily parsed and traditionally much of it has remained walled away in the hands of large...