[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (70 articles)

|

// AI-powered summary generated at 16:00

> CVE-2026-68399 bpf: Fix UAF in sock clone early bailouts
Information published.
> CVE-2026-64563 rhashtable: clear stale iter->p on table restart
Information published.
> Only Half of UK Manufacturers Have a Cyber Incident Response Plan
Make UK reveals major cyber resilience gaps as 30% of UK manufacturers report recent cyber incidents
> CVE-2026-68288 net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD
Information published.
> CVE-2026-68388 smb/client: handle overlapping allocated ranges in fallocate
Information published.
> Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine
Attackers shut down a steam turbine and the process-water treatment system at a Polish combined heat and power plant by coming in over the private cellular network the local grid operator uses to reach remote equipment. The plant supplies heat to roughly 50,000 residents. Recovery began at about 7:...
> CVE-2026-65819 gopacket: Multiple layer decoders panic on crafted packets (out-of-bounds/underflow) enabling unauthenticated remote DoS via DecodingLayerParser
Information published.
> CVE-2026-68363 wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request
Information published.
> GPT-5.6-Cyber refuses security researchers’ requests far less often
GPT-5.6-Cyber is a new OpenAI model built on GPT-5.6 Sol, trained to find zero-day vulnerabilities and build exploit chains, with fewer refusals on higher-risk, dual-use work. Model is available only through Daybreak Red, the higher tier of OpenAI’s vetted access program for cybersecurity profession...
> CVE-2026-71557 go-git: Malicious reference names may modify files outside the reference storage
Information published.
> CVE-2026-68323 tipc: serialize udp bearer replicast list updates
Information published.
> Mozilla Issues New Firefox GPG Key Following Exposure
The previous GPG signing subkey was inadvertently added to a GitHub repository and Mozilla decided to revoke it. The post Mozilla Issues New Firefox GPG Key Following Exposure appeared first on SecurityWeek.
> CVE-2026-71556 go-git: Worktree operations may follow symlinks
Information published.
> CVE-2026-6879 Quadratic Behavior in xml.etree.ElementPath Index Predicates
Information published.
> Who will be the Stanislav Petrov in your organization?
The recent news coverage of “rogue AI” systems hacking innocent companies reminded me of one of the world’s most unsung heroes and genuinely someone who may well have saved the world. In 1983, the USSR’s early warning systems reported that the United States had launched nuclear missiles towards the...
> CVE-2026-55969 Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: integer overflow in TProtocol::checkReadBytesAvailable()
Information published.
> CVE-2026-64539 Bluetooth: eir: Fix stack OOB write when prepending the Flags AD
Information published.
> BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins
Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platform's plugins team to temporarily disable their downloads. "Unlike traditional software supply chain attacks, zero source code files wer...
> CVE-2026-43871 Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byte-count limit
Information published.
> CVE-2026-68210 media: stm32: dcmi: unregister notifier on probe failure
Information published.