Today is Microsoft's August 2026 Patch Tuesday, and with it comes security updates for a massive 400 flaws, including one actively exploited and two publicly disclosed zero-day vulnerabilities. [...]
The airline deactivated the network after the crew realized someone was messing with the in-flight system. The feds are investigating.
The post Delta investigates in-flight Wi-Fi spoofing on post-DEF CON flight from Las Vegas appeared first on CyberScoop.
Your smart home may know more about you than you realize. Learn how connected devices collect data and how to better protect your privacy.
This month we got patches for 418 vulnerabilities. Of these, 62 are critical, 1 is being exploited in the wild, and 2 were publicly disclosed as zero-days. Notable fixes include Windows privilege escalation, container tampering, and critical QUIC and DNS Server remote code execution bugs.
Zoom patches a zero-click flaw that could let a meeting participant execute code on another userâs computer through the annotation feature. Zoom has patched four vulnerabilities, including a critical zero-click flaw, tracked as CVE-2026-53413, in its annotation feature. CVE-2026-53413 is a memory co...
La Commission de protection des informations personnelles (PIPC) sud-coréenne organise une troisiÚme phase de candidatures, du 11 au 31 août, pour son opération pilote de consultation préalable destinée aux mandataires exerçant le droit à la transmission des données personnelles.Cette initiative vis...
Microsoft has released Windows 11 KB5121003 and KB5120240 cumulative updates for versions 25H2/24H2 and 23H2 to fix security vulnerabilities, bugs, and add new features. [...]
Every Signal chat starts the same way: the client asks the Signal server for the public key associated with your contactâs phone number. But how do you know the server gave you the right key? A compromised server could provide a false public key, allowing the client to encrypt messages to an attacke...
Key Points Introduction Since early 2026, Check Point Research has tracked a wave of the Operation Dream Job campaign. This wave primarily targeted the defense sector worldwide, with a particular emphasis on companies operating in the aerospace and aviation industries. We observed the threat actor d...
The security defects could be exploited for arbitrary code execution and denial-of-service.
The post Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws appeared first on SecurityWeek.
Security researchers found a way to enter Microsoft SharePoint servers as any user, including an administrator, with no valid account. A significant part of the work that found it was done through an AI agent.
The flaw, tracked as CVE-2026-55040 (CVSS 9.1), affects SharePoint Server Subscription Ed...
ExfilSquad targets 13 organizations, exploiting cloud portals for data theft and using torrents to spread stolen information and amplify damage. Resecurity is tracking the activity of ExfilSquad â the group announced new victims this week. ExfilSquad is a new cybercrime group that emerged in mid-202...
The ransomware group known as DeadLock has been observed using decentralized infrastructure to facilitate victim communications and data leak operations in a bid to improve operational resilience.
"Its recovery ecosystem combines the Session messaging network with blockchain-backed services that st...
The warning affects recent buyers of Steam hardware, including the hugely popular Steam Deck.
Updating WordPress directly on a live website can cause avoidable problems. A plugin update might break checkout, or a theme change could create layout issues visitors see immediately.
A WordPress staging site gives you a separate place to test changes before they reach your live website.
Staging re...
This is why we can't have nice things, people
Iran-linked hackers targeted Water Infrastructure in New Jersey and Alabama, bringing confirmed attacks to at least 12 states, with limited disruption. The wave of cyberattacks targeting US water infrastructure has reached New Jersey and Alabama, bringing the confirmed count to at least 12 states si...
AI pentesting can flood teams with findings they cannot validate. The real challenge is managing âvalidation debtâ as discovery scales. AI pentesting has a âSorcererâs Apprenticeâ problem. Enchant a broom to fetch water, and it will fetch water, relentlessly, long after the workshop has flooded. The...
L'autorité danoise de protection des données a émis une critique formelle à l'encontre d'un établissement de crédit, non pas pour la suppression de journaux d'accÚs, mais pour sa gestion défaillante d'une demande de droit d'accÚs, notamment en tentant de conditionner un remboursement à l'abandon de...
L'autorité de protection des données et de la transparence de Saxe (SDTB) a enrichi sa foire aux questions (FAQ) afin de fournir des orientations sur le traitement des données personnelles en milieu scolaire.Les nouvelles directives portent sur la communication numérique, précisant que les enseignan...