[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (115 articles)

|

// AI-powered summary generated at 20:00

> Secure enterprise sharing with access reviews for Microsoft 365
Microsoft 365 makes sharing files easy, but access can remain long after its original purpose has ended, leaving organizations with little visibility into who can still reach sensitive data. tenfold Software explains how centralized access governance and owner-driven reviews can help identify and re...
> Researchers used Anthropic’s Claude to hack into OpenAI
Security researchers used Anthropic’s Claude to exploit vulnerabilities in OpenAI’s systems, taking over employee accounts and gaining access to an internal code repository before reporting the flaws.
> Microsoft Teams will let admins block custom file extensions
Microsoft Teams will soon let administrators tweak the list of file extensions commonly associated with security threats to meet their company's security requirements. [...]
> Comprendre le licensing Microsoft : contrats, familles et canaux d’achats
Maîtrisez le licensing Microsoft: contrats, comptes de facturation et familles M365 pour éviter les coûts cachés et les migrations surprises. Le post Comprendre le licensing Microsoft : contrats, familles et canaux d’achats a été publié sur IT-Connect.
> Brevo : des scripts ClickFix injectés sur les sites de ses clients, avec une backdoor pour WordPress
Le 14 septembre 2026, les scripts Brevo intégrés aux sites de ses clients ont diffusé une attaque ClickFix et une backdoor WordPress. Voici ce que l'on sait. Le post Brevo : des scripts ClickFix injectés sur les sites de ses clients, avec une backdoor pour WordPress a été publié sur IT-Connect.
> New Settra Ransomware Variant Deployed in Attacks on Retail and Manufacturing
Huntress researchers highlighted a new ransomware variant, named Settra, and the post-compromise techniques used in two recent attacks
> Hacking group ‘NightEagle’ targeting China’s high-tech sector expands operations to Russia
Over the past year, Russian cybersecurity firm Kaspersky said it investigated several incidents involving the group at Russian businesses.
> Webinar: Which Google Workspace security controls actually matter?
Fast-growing companies face countless recommendations for securing Google Workspace, but not every control provides the same value. This webinar examines real-world breaches to explore which security controls matter most, which may be overrated, and where lean security teams should focus their resou...
> Ubuntu 26.04 LTS Linux Kernel Critical Privilege Escalation Fix USN-8726-2
Several security issues were fixed in the Linux kernel.
> Ubuntu 24.04 LTS Linux Nvidia Tegra Escalation Risks - Urgent Alert 8781-1
Several security issues were fixed in the Linux kernel.
> Meta’s Copyright System Is Being Weaponized Against Albanian Protesters
After three months of daily anti-government protests—dubbed the Flamingo Revolution—the sudden mass suspension of Instagram accounts has led to fears of brigading against demonstrators.
> Ubuntu 24.04 LTS Azure FIPS Essential Security Patch USN-8761-2 Released
Several security issues were fixed in the Linux kernel.
> Ubuntu Linux Kernel Update Critical Networking Vulnerability USN-8730-3
A security issue was fixed in the Linux kernel.
> InfoSec News Nuggets – 09/18/2026
Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks A maximum-severity flaw in Cisco Identity Services Engine and ISE-PIC, tracked as CVE-2026-76460, is being actively exploited to bypass authentication on the web management interface through a crafted request to an i...
> Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation
Microsoft has released fixes for a maximum-severity security flaw in Azure AI Foundry that could be exploited to achieve privilege escalation. No customer action is required. The vulnerability, tracked as CVE-2026-85889, carries a CVSS score of 10.0. "Missing authentication for critical function i...
> AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code
Hacktron researchers earned a bug bounty after demonstrating access to OpenAI employee accounts.  The post AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code appeared first on SecurityWeek.
> Microsoft fixes bug behind ‘Defender Antivirus is turned off’ alerts
Microsoft has resolved a known issue that causes incorrect alerts warning that Defender Antivirus was turned off after installing recent updates. [...]
> Forensic Focus Digest, September 18 2026
Discover what’s new on Forensic Focus – explore why forensic imaging is about workflow as much as speed, examine what institutional silence says about DFI well-being, see how semantic search can uncover what keyword searches miss with BelkaGPT, and more.
> 23 Million User Records Compromised in Gyazo Data Breach 
Gyazo maker Helpfeel said the attacker exploited a vulnerability in its image upload server to gain unauthorized access. The post 23 Million User Records Compromised in Gyazo Data Breach  appeared first on SecurityWeek.
> Are AIs Still Struggling with CAPTCHAs?
Anthropic’s recent security-incident document contains a bit about how CAPTCHAs are still frustrating Claude. In the transcript, the Claude model that is so powerful that Anthropic is gatekeeping access to it appeared to slam its virtual head against the wall solving a simple image identification te...