[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> Device Bound Session Credentials lands in Chrome on macOS
Device Bound Session Credentials (DBSC) is Chrome's answer to session cookie theft, usually by InfoStealer malware. Instead of a cookie being a bearer token that works anywhere it's pasted, DBSC binds the session to a private key that lives in your device's hardware and
> What we know about the cryptocurrency theft through Adform ads | Kaspersky official blog
The Adform platform was briefly hijacked to distribute a crypto-stealing script. Here’s everything we know about the incident, plus tips on how to protect yourself.
> SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities
SAP released 28 new and two updated security notes, including four notes dealing with critical-severity bugs. The post SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities appeared first on SecurityWeek.
> Google suspend son IA d’images dans Google Earth
Google suspend une fonction d’IA de Google Earth après des alertes sur les fausses images et la désinformation.
> US Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’
The Water Watch Center launched at DEF CON aims to help under-resourced utilities protect their systems against hackers. The post US Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’ appeared first on SecurityWeek.
> CVE-2026-70339 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
> CVE-2026-65680 Microsoft OneDrive for MacOS Elevation of Privilege Vulnerability
Improper link resolution before file access ('link following') in Microsoft OneDrive allows an authorized attacker to elevate privileges locally.
> CVE-2026-62917 Microsoft SharePoint Server Spoofing Vulnerability
Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
> CVE-2026-62839 Microsoft SharePoint Server Spoofing Vulnerability
Insufficiently protected credentials in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
> CVE-2026-58639 Microsoft SharePoint Server Spoofing Vulnerability
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
> CVE-2026-65767 Microsoft Teams for Android and iOS Spoofing Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized attacker to perform spoofing over a network.
> CVE-2026-62898 Microsoft QUIC Information Disclosure Vulnerability
Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network.
> CVE-2026-62738 Windows Management Instrumentation Information Disclosure Vulnerability
Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally.
> CVE-2026-71331 Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability
Integer overflow or wraparound in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker to execute code over a network.
> CVE-2026-70354 .NET Core Remote Code Execution Vulnerability
Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
> CVE-2026-70337 Microsoft PowerShell Remote Code Execution Vulnerability
Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network.
> CVE-2026-70338 Microsoft PowerShell Security Feature Bypass Vulnerability
Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.
> CVE-2026-70326 Microsoft SharePoint Server Elevation of Privilege Vulnerability
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
> CVE-2026-70306 Microsoft Office SharePoint Spoofing Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
> CVE-2026-70130 Microsoft Office Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.