[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (37 articles)

|

// AI-powered summary generated at 12:00

> CVE-2026-72522 libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions.
Information published.
> CVE-2026-68312 cifs: fix cifsFileInfo leak on kmalloc failure in deferred close drain paths
Information published.
> Only Half of UK Manufacturers Have a Cyber Incident Response Plan
Make UK reveals major cyber resilience gaps as 30% of UK manufacturers report recent cyber incidents
> CVE-2026-66484 Path Traversal in GNU cpio
Information published.
> CVE-2026-68397 net/iucv: take a reference on the socket found in afiucv_hs_rcv()
Information published.
> Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine
Attackers shut down a steam turbine and the process-water treatment system at a Polish combined heat and power plant by coming in over the private cellular network the local grid operator uses to reach remote equipment. The plant supplies heat to roughly 50,000 residents. Recovery began at about 7:...
> CVE-2026-68155 libceph: Reject monmaps advertising zero monitors
Information published.
> CVE-2026-68249 drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON()
Information published.
> GPT-5.6-Cyber refuses security researchers’ requests far less often
GPT-5.6-Cyber is a new OpenAI model built on GPT-5.6 Sol, trained to find zero-day vulnerabilities and build exploit chains, with fewer refusals on higher-risk, dual-use work. Model is available only through Daybreak Red, the higher tier of OpenAI’s vetted access program for cybersecurity profession...
> CVE-2026-66486 Improper Output Encoding in GNU cpio
Information published.
> CVE-2026-68148 fscrypt: Add missing superblock check in find_or_insert_direct_key()
Information published.
> Mozilla Issues New Firefox GPG Key Following Exposure
The previous GPG signing subkey was inadvertently added to a GitHub repository and Mozilla decided to revoke it. The post Mozilla Issues New Firefox GPG Key Following Exposure appeared first on SecurityWeek.
> CVE-2026-68197 wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper
Information published.
> CVE-2026-68272 drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1
Information published.
> Who will be the Stanislav Petrov in your organization?
The recent news coverage of “rogue AI” systems hacking innocent companies reminded me of one of the world’s most unsung heroes and genuinely someone who may well have saved the world. In 1983, the USSR’s early warning systems reported that the United States had launched nuclear missiles towards the...
> CVE-2026-15534 Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch
Information published.
> CVE-2026-68427 gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings
Information published.
> BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins
Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platform's plugins team to temporarily disable their downloads. "Unlike traditional software supply chain attacks, zero source code files wer...
> CVE-2026-68333 dpaa2-switch: put MAC endpoint device on disconnect
Information published.
> CVE-2026-68315 sctp: validate stream count in sctp_process_strreset_inreq()
Information published.