[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (70 articles)

|

// AI-powered summary generated at 16:00

> ZDI-26-551: OriginLab OriginPro OGG File Parsing Memory Corruption Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab OriginPro . User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The f...
> ZDI-26-552: OriginLab Origin Viewer OPJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. Th...
> Previously unseen entry vector used to breach Polish energy plant
The December 29 cyberattack on a Polish combined heat and power (CHP) plant was the first observed case of attackers gaining access to an OT network through a private APN, according to CERT Polska. The private APN is a dedicated mobile network that a Distribution System Operator (DSO), the company r...
> ZDI-26-553: OriginLab Origin Viewer OGW File Parsing Memory Corruption Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. Th...
> ZDI-26-554: Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels RAS Client. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The fol...
> Your security vendor gets the frontier cyber model, you get the findings
Selected red team specialists can now use OpenAI’s cyber models to find and exploit weaknesses in client applications and infrastructure. Those clients never get the models themselves. That split is the design of the Daybreak Cyber Partner Program, which OpenAI expanded on August 10: access to the u...
> ZDI-26-555: Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels RAS Client. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The fol...
> ZDI-26-556: Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels RAS Client. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The fol...
> Cybersecurity jobs available right now: August 11, 2026
CTI Detection Engineer Department of Parliamentary Services | Australia | Hybrid – View job details As a CTI Detection Engineer, you will lead the detection lifecycle by identifying detection gaps, developing and validating detection logic, deploying and tuning analytics, maintaining cyber threat in...
> Transférer des fichiers entre un hÎte et une VM Vagrant
Découvrez deux méthodes pour transférer des fichiers entre l'hÎte et une VM Vagrant : le plugin vagrant-scp et les dossiers partagés (synced_folder). Le post Transférer des fichiers entre un hÎte et une VM Vagrant a été publié sur IT-Connect.
> Debian Caddy Important Access Control Breaches DSA-6429-1 CVE-2026-27585
Multiple vulnerabilities in the Caddy web server can lead to unauthorized access and other security issues; users are urged to upgrade to version 2.6.2-12+deb13u1 for protection.
> The future of AI security research isn’t autonomous, it’s human-amplified
Meet HTTP Terminator, a new AI system that has identified hundreds of websites vulnerable to HTTP request smuggling, hacked them live at scale, and even identified a “genuinely new class” of vulnerability, dubbed “shared-parser confusion.” But it didn’t do it alone; it was...
> ISC Stormcast For Tuesday, August 11th, 2026 https://isc.sans.edu/podcastdetail/10046, (Tue, Aug 11th)
> Charm
La sociĂ©tĂ© Charm a annoncĂ© qu'un accĂšs non autorisĂ© Ă  ses magasins Charm Honten 1 et 2 avait Ă©tĂ© dĂ©tectĂ© le 12 aoĂ»t 2026, suite Ă  une intrusion par un tiers le 11 aoĂ»t 2026. L'entreprise enquĂȘte actuellement sur l'Ă©tendue des dĂ©gĂąts, confirmant que certaines informations clients ont pu fuiter. Envir...
> Brazosport College
Les systĂšmes de Brazosport College sont restĂ©s hors ligne suite Ă  un incident de cybersĂ©curitĂ© dont la cause reste inconnue. L'incident a Ă©tĂ© dĂ©couvert le lundi par l'Ă©quipe informatique du collĂšge, et des spĂ©cialistes externes ont Ă©tĂ© appelĂ©s pour mener l'enquĂȘte.
> ClickFix campaign abuses Deno runtime for infostealer delivery
Lures on compromised WordPress sites led to installation of Deno and a Python-based infostealer
> Darlington County
Le comté de Darlington, en Caroline du Sud, a dû isoler certains de ses systÚmes informatiques suite à un incident de cybersécurité qui a perturbé les téléphones et certains services gouvernementaux. Les services d'urgence (911) sont restés opérationnels. L'incident est survenu mercredi, et les auto...
> Ágape Consultoria
Vingt organisations municipales du capixaba (État du EspĂ­rito Santo) ont Ă©tĂ© touchĂ©es par une cyberattaque visant leurs portails publics. L'attaque, attribuĂ©e au groupe hacker BLCKORDER, a entraĂźnĂ© une indisponibilitĂ© des services en ligne. Les autoritĂ©s locales et l'entreprise prestataire de servic...
> Abuse of alternative runtime environments Deno-tes defender headaches
Attack TTPs combine fileless execution, wide LOLBin use
> CH BIOTECH R&D CO., LTD.
Le 11 août 2026, la CH Biotech a subi une cyberattaque ayant touché une partie de ses systÚmes d'information. Selon les premiÚres évaluations, l'incident n'a pas d'impact significatif sur les opérations de l'entreprise. Pour y répondre, la société a activé ses mécanismes de défense, engagé des cabin...