[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (101 articles)

|

// AI-powered summary generated at 16:00

> Parents take on Meta, TikTok, Google, and Snap in 3,000 youth safety lawsuits
It's the biggest legal challenge yet to addictive social media design and its impact on children.
> White House Mobilizes Security Firms for Operations Against Foreign Cybercrime Gangs
Contracts may require a $1 million bond, which will be forfeited if a company fails to comply with operational requirements. The post White House Mobilizes Security Firms for Operations Against Foreign Cybercrime Gangs appeared first on SecurityWeek.
> Akira Affiliate Crashes Ransomware After Attempting EDR Evasion
Huntress documents how a ransomware affiliate sabotaged its own attack with an anti-EDR effort
> CBP Workers Allegedly Used Government Databases to Spy on Exes, Crushes, and Colleagues
Records obtained by WIRED detail hundreds of allegations of Customs and Border Protection workers misusing internal tools to look up romantic interests and track colleagues’ cell phones.
> Critical VMware vCenter Vulnerability in Attackers’ Crosshairs
Tracked as CVE-2026–59310, the directory traversal bug allows remote attackers to execute arbitrary code. The post Critical VMware vCenter Vulnerability in Attackers’ Crosshairs appeared first on SecurityWeek.
> Black Hat USA 2026: What the Hugging Face hack tells us about human responsibility
The incident involving OpenAI models shows that autonomous hacks make human oversight more important, not less
> Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’
Dropped on Patch Tuesday, the exploit allows any user to spawn a shell with System privileges. The post Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’ appeared first on SecurityWeek.
> SharePoint CVE-2026-55040 Comes Under Attack Following Public Exploit
Attackers are exploiting SharePoint flaw CVE-2026-55040 after a public PoC was released, allowing unauthenticated users to impersonate administrators. Attackers started exploiting CVE-2026-55040 (CVSS score of 9.1), a critical SharePoint authentication bypass patched in July, within days of Rapid7 r...
> ICO Reprimands Criminal Records Office After 2023 Breach
The ICO has issued a formal reprimand to ACRO after patching and security monitoring failures led to a breach
> Microsoft wants you to rethink your approach to cyber defense
Cyber defenders need to shake off traditional best practices and switch from reactive patching to building inherently resilient systems in the face of AI-accelerated vulnerability discovery, according to a senior security manager at Microsoft. David Weston, group manager in...
> Storm-1175 Replaces Medusa With New StormEncryptor Ransomware
Microsoft says China-linked Storm-1175 is using a new ransomware called StormEncryptor, replacing Medusa in its latest attacks. Microsoft says China-linked, financially motivated threat actor Storm-1175 has begun using a new ransomware strain called StormEncryptor. The group previously relied on Med...
> Cisco fixes vulnerability exploited to DoS its firewalls (CVE-2026-20349)
A high-severity vulnerability (CVE-2026-20349) is being leveraged by attackers to temporarily interrupt the operation of Cisco firewalls, the company has confirmed. The flaw has been added to CISA’s Known Exploited Vulnerabilities catalog and needs to be remediated by US civilian federal agencies by...
> North Korean Lazarus Group Uses Windows Zero-Day in Operation Dream Job
Lazarus targets defense professionals with fake Lockheed Martin jobs, exploiting a Windows zero-day to deploy backdoors and evade security controls. Check Point Research has uncovered a new wave of Operation Dream Job, the long-running North Korean campaign that lures defense and aerospace professio...
> Passwords stored in public Google Doc then showed up in search results
Developer spotted hostname and credential string lurking in autocomplete
> Attackers Exploit SharePoint Authentication Bypass After Public PoC Release
Threat actors have begun to exploit a newly disclosed Microsoft SharePoint vulnerability following the release of a proof-of-concept (PoC) code. The vulnerability in question is CVE-2026-55040 (CVSS score: 9.1), which refers to a critical security feature bypass that stems from weak authentication....
> Debian DSA-6433-1 xdg-dbus-proxy Important Policy Bypass
A vulnerability in xdg-dbus-proxy allowed malicious Flatpak applications to monitor D-Bus signals; this has been fixed in version 0.1.6-1+deb13u2 for Debian's stable distribution.
> ZDI-26-568: Linux Kernel Net Scheduler Race Condition Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5.
> ZDI-26-569: Linux Kernel Net Scheduler True Link Equalizer Race Condition Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5.
> Four corporate investigation mistakes organizations make under pressure
In this Help Net Security video, Christine Gadsby, VP and Chief Security Advisor at BlackBerry, explains why corporate investigations go wrong before the forensic team arrives. The first hours matter more than leaders assume. Access gets granted, conversations start, and decisions get made that late...
> ZDI-26-570: Linux Kernel IGMP Subsystem Race Condition Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5.