[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (17 articles)

|

// AI-powered summary generated at 08:01

> CVE-2026-59113 Visual Studio Code Remote Code Execution Vulnerability
Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network.
> CVE-2026-58612 PowerShell Information Disclosure Vulnerability
Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized attacker to disclose information over a network.
> Automate your business cloud storage without compromising privacy
Automate backups, sharing, and file management for your business with a cloud storage CLI that protects your data with end-to-end encryption.
> CVE-2026-49179 Windows Active Directory Domain Services Remote Code Execution Vulnerability
Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network.
> CVE-2026-54984 Windows Imaging Component Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally.
> North Korean remote IT staffer worked for US government agency, says FBI
The investigation shows that North Koreans are able to infiltrate government agencies, as well as private organizations and crypto exchanges.
> CVE-2026-54113 Remote Procedure Call Denial of Service Vulnerability
Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network.
> CVE-2026-40375 Microsoft Dynamics Business Central Information Disclosure Vulnerability
Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network.
> Sexual predators targeting online accounts for intimate images, FBI warns
The FBI is warning that criminals are breaking into social media to steal and distribute non-consensual intimate images and videos.
> CVE-2026-63520 Microsoft SharePoint Server Remote Code Execution Vulnerability
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
> CVE-2026-63516 Microsoft SharePoint Server Spoofing Vulnerability
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
> Mozilla updates GPG signing key for Firefox releases after exposure
Mozilla announced today that it updated the GPG key used to sign Firefox and Thunderbird releases after it was accidentally exposed on GitHub. [...]
> CVE-2026-63512 Microsoft SharePoint Server Tampering Vulnerability
Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network.
> CVE-2026-63514 Microsoft SharePoint Server Remote Code Execution Vulnerability
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
> Vague Task, Total Access: When AI Delegation Becomes a Security Risk
AI agents can improvise beyond the intended scope of a task when they are given broad access to enterprise systems and data. Token Security explains why organizations need to define agent intent and continuously enforce permissions around what each agent was actually created to do. [...]
> CVE-2026-62837 Microsoft SharePoint Server Information Disclosure Vulnerability
Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
> CVE-2026-62827 Microsoft SharePoint Server Elevation of Privilege Vulnerability
Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
> OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development
OpenAI on Monday unveiled a new cybersecurity-focused model called GPT‑5.6‑Cyber that it said is focused on vulnerability research, penetration testing, and incident response. "Built on GPT‑5.6 Sol, it is trained to improve capabilities on several specialized cybersecurity tasks (e.g., finding zero...
> CVE-2026-62829 Microsoft SharePoint Server Spoofing Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
> CVE-2026-57105 Microsoft Office SharePoint Spoofing Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.