[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (51 articles)

|

// AI-powered summary generated at 12:01

> Oracle Linux 9 nghttp2 Moderate HTTP Request Smuggling ELSA-2026-54662
Oracle Linux 9 has released updated rpms for libnghttp2 to address CVE-2026-58055, fixing HTTP request smuggling and response-queue poisoning vulnerabilities.
> Oracle Linux gnome-remote-desktop Advisory ELSA-2026-54512 CVE-2026-18358
Oracle Linux Security Advisory ELSA-2026-54512 announces the update of gnome-remote-desktop for Oracle Linux 10, addressing CVE-2026-18358 by backporting connection throttling.
> Autonomous AI attacks pose 'clear and present danger' to critical infrastructure
Weaponized agents could turn digital intrusions into kinetic disasters, experts warn
> Secure all your internal vibe-coded applications — in one click
Introducing Cloudflare Access for Workers. Attach an Access policy directly to a Worker and it applies everywhere that Worker runs — routes, custom domains, workers.dev, and previews — automatically.
> New Mirai-Based Linux Botnet ‘Evooo1Bot’ Turns Victims Into Proxies
Evooo1Bot is a newly observed botnet based on the Mirai framework but equipped with advanced features, turning edge devices into persistent proxies
> Apple now uses iPhone alerts for targets of mercenary spyware
Apple explains how Threat Notifications help protect iPhone users targeted by mercenary spyware.
> WhatsApp is testing a new warning for scam messages
An optional new feature uses on-device AI to flag messages that look like scams.
> In Other News: Rapid7 Layoffs, Hacking a Boeing 737, Refrigeration System Vulnerabilities
Noteworthy stories that might have slipped under the radar: government AI platform deal sparks outrage, North Korean IT worker breaches federal agency, DEF CON attendee blamed for Delta flight disruption. The post In Other News: Rapid7 Layoffs, Hacking a Boeing 737, Refrigeration System Vulnerabilit...
> Shell investigates 'potential incident' after Clop data theft claims
Oil giant Shell has confirmed it is investigating a potential security incident after the Clop ransomware gang claimed it stole 89GB of data. [...]
> Cyberharcèlement : la Belgique prépare un bannissement numérique
La Belgique prépare un bannissement numérique contre le cyberharcèlement, avec identification judiciaire et contrôle des comptes.
> Trivy, Not LiteLLM Behind the 2,500 Org Compromise
Over 95% of the affected companies were exposed before the malicious LiteLLM packages were published. The post Trivy, Not LiteLLM Behind the 2,500 Org Compromise appeared first on SecurityWeek.
> Who’s Tracking You? Use This New Service to Find Out
It can be daunting to determine who's responsible for showing ads on the websites we visit, or who's harvesting data from the mobile apps we use every day. That information is already semi-public, but it is not easily parsed and traditionally much of it has remained walled away in the hands of large...
> Debian Python-httplib2 Important Denial of Service Vuln DSA-6441-1
Debian Security Advisory DSA-6441-1 announces a vulnerability in python-httplib2 affecting stable distribution trixie, with an upgrade to version 0.22.0-1+deb13u1 recommended to prevent denial of service.
> curl performance
tldr: the live version is here: https://curl.se/perf/ How fast is “fast” and is it good enough? Does it run as fast now as it did before or was there a regression? What exactly needs to be fast? How fast is it? These are questions that many projects and products face, and in curl we are … Continue r...
> New Android malware relays bank cards to fraudsters while victims still hold them
Group-IB researchers discovered WindRelay, a new Android malware built to capture live payment card data over NFC (Near Field Communication) and relay it to attackers in real time. WindRelay is paired with the SpyNote remote access trojan, which gives attackers remote access to a victim’s device. At...
> Infosec News Nuggets — August 14, 2026
vCenter Flaw Exploited Just Five Days After Disclosure A critical directory-traversal flaw in VMware vCenter’s Syslog server, rated CVSS 9.8, was already being exploited within five days of Broadcom’s disclosure, with researchers tracing 361 victim IP addresses across 47 countries. The attacker depl...
> Chrome DevTools Technique Enables Authenticated Session Hijacking in Live Windows Browsers
Cybersecurity researchers have detailed a post-exploitation technique that enables the Chrome DevTools Protocol (CDP) inside a running Google Chrome or Microsoft Edge process on Windows, allowing an operator to access cookies, saved data, and authenticated browser sessions. The technique assumes th...
> If the Markets Reject OpenAI and Anthropic, the US Should Nationalize Them
This essay was written with Nathan E. Sanders, and originally appeared in The Guardian. OpenAI, and then Anthropic, were each formed by AI developers who feared unrestrained corporate AI development—specifically, that companies like Google and Meta would steer the technology towards deleterious, may...
> Google Cloud Sets Out Post-Quantum Roadmap With 2029 Readiness Goal
Google Cloud outlines its roadmap to full post-quantum cryptography readiness, with key milestones targeted for 2027 and 2028. The post Google Cloud Sets Out Post-Quantum Roadmap With 2029 Readiness Goal appeared first on SecurityWeek.
> CTM360 Uncovers Over 3,000 Recruitment Phishing URLs Using Browser-in-the-Browser (BitB) Credential Traps
Cybersecurity researchers have uncovered a large-scale, global recruitment-themed phishing campaign that uses fake interview scheduling pages and Browser-in-the-Browser (BitB) windows to steal Google and Facebook credentials and, in more advanced cases, relay multi-factor authentication (MFA) prompt...