[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (70 articles)

|

// AI-powered summary generated at 16:00

> CVE-2026-64655 GitHub CLI: Attestation Verification Bypass via Unescaped Regex Metacharacters in SAN Matching
Information published.
> CVE-2026-68407 wifi: nl80211: free RNR data on MBSSID mismatch
Information published.
> Only Half of UK Manufacturers Have a Cyber Incident Response Plan
Make UK reveals major cyber resilience gaps as 30% of UK manufacturers report recent cyber incidents
> CVE-2026-68235 drm/amd/display: dce100: skip non-DP stream encoders for DP MST
Information published.
> CVE-2026-61477 Libvirt: libvirt: newline injection in network xml dns txt/srv fields allows dnsmasq config directive injection
Information published.
> Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine
Attackers shut down a steam turbine and the process-water treatment system at a Polish combined heat and power plant by coming in over the private cellular network the local grid operator uses to reach remote equipment. The plant supplies heat to roughly 50,000 residents. Recovery began at about 7:...
> CVE-2026-71497 jsoup: Cleaner may expose markup with custom raw-text elements
Information published.
> CVE-2026-68412 wifi: cfg80211: Fix an error handling path in cfg80211_wext_siwscan()
Information published.
> GPT-5.6-Cyber refuses security researchers’ requests far less often
GPT-5.6-Cyber is a new OpenAI model built on GPT-5.6 Sol, trained to find zero-day vulnerabilities and build exploit chains, with fewer refusals on higher-risk, dual-use work. Model is available only through Daybreak Red, the higher tier of OpenAI’s vetted access program for cybersecurity profession...
> CVE-2026-68097 ksmbd: validate ACE size against SID sub-authorities
Information published.
> CVE-2026-68273 drm/amdgpu: Fix context pstate override handling
Information published.
> Mozilla Issues New Firefox GPG Key Following Exposure
The previous GPG signing subkey was inadvertently added to a GitHub repository and Mozilla decided to revoke it. The post Mozilla Issues New Firefox GPG Key Following Exposure appeared first on SecurityWeek.
> CVE-2026-64388 smb/client: fix chown/chgrp with SMB3 POSIX Extensions
Information published.
> CVE-2026-64377 cpufreq: qcom-cpufreq-hw: Fix possible double free
Information published.
> Who will be the Stanislav Petrov in your organization?
The recent news coverage of “rogue AI” systems hacking innocent companies reminded me of one of the world’s most unsung heroes and genuinely someone who may well have saved the world. In 1983, the USSR’s early warning systems reported that the United States had launched nuclear missiles towards the...
> CVE-2026-64513 KVM: x86: Unconditionally recompute CR8 intercept on PPR update
Information published.
> CVE-2026-64525 xfrm: move policy_bydst RCU sync from per-netns .exit to .pre_exit
Information published.
> BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins
Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platform's plugins team to temporarily disable their downloads. "Unlike traditional software supply chain attacks, zero source code files wer...
> CVE-2026-64523 net/handshake: Take a long-lived file reference at submit
Information published.
> CVE-2026-64652 GitHub CLI: Partial token disclosure in `gh auth status` output
Information published.