> TODAY'S SUMMARY (112 articles)
Today's cybersecurity news highlights several significant threats and trends:
1. Labcorp faces a $2.3 million fine due to cybersecurity failings and is implementing enhanced data security measures, including a new incident response plan.
2. Cryptocurrency exchange Bitget reports a staggering $351.6 million theft by suspected North Korean hackers, prompting investigations and withdrawal suspensions.
3. A critical vulnerability in the Elementor WordPress plugin allows unauthenticated attackers to create admin accounts, emphasizing the ongoing risk of exploited software flaws.
4. Fake desktop applications targeting payroll services have emerged, tricking HR staff into granting remote access to attackers.
5. CISA warns of exploited flaws in Adobe and WSO2 products, adding them to its Known Exploited Vulnerabilities catalog, highlighting the urgency for organizations to patch these vulnerabilities.
|
// AI-powered summary generated at 20:00
Attack TTPs combine fileless execution, wide LOLBin use
Le 11 août 2026, la CH Biotech a subi une cyberattaque ayant touché une partie de ses systèmes d'information. Selon les premières évaluations, l'incident n'a pas d'impact significatif sur les opérations de l'entreprise. Pour y répondre, la société a activé ses mécanismes de défense, engagé des cabin...
PraisonAI praisonaiagents 1.6.77 - Remote Code Execution
Blocksy Companion 2.1.46 - RCE
Une vulnérabilité a été découverte dans Docker. Elle permet à un attaquant de provoquer une atteinte à l'intégrité des données.
Apache Gravitino 1.2.1 - SSRF
De multiples vulnérabilités ont été découvertes dans Postfix. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service à distance, un contournement de la politique de sécurité et un problème de sécurité non spécifié par l'éditeur.
Une vulnérabilité a été découverte dans CPython. Elle permet à un attaquant de provoquer un déni de service à distance.
Ray 2.56.0 - Directory Traversal & Local File Inclusion
De multiples vulnérabilités ont été découvertes dans les produits SAP. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et une atteinte à la confidentialité des données.
De multiples vulnérabilités ont été découvertes dans SPIP. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une injection SQL (SQLi) et une falsification de requêtes côté serveur (SSRF).
Planyo_Online_Reservation_System 3.0 - Arbitrary File Read via SSRF
De multiples vulnérabilités ont été découvertes dans OpenSSH. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.
LuCI DHCPv6 - Lease Hostname Stored Cross-Site Scripting
mcp-server-kubernetes 3.8.x - Argument Injection
Imagine if McDonald’s could use trademark law to control how you use the term “fast food.” Or if the Canadian government could stop you from using the word “Canada” in the title of a book about the country and its people. That wouldn’t just be absurd; it would be an unacceptable obstacle to criticis...
Hackers breached a heat-and-power plant facility in Poland, which supplies heat to about 50,000 residents, using a private APN (Access Point Name) to access an OT (Operational Technology) network. [...]
Deux pirates revendiquent le piratage d'un professionnel du cloud et l’accès à 159 instances contenant des données clients.
Oracle Linux 7 has updated rpms to fix vulnerabilities CVE-2026-33416 and CVE-2026-25646 in libpng12 packages, enhancing security against issues like use-after-free and heap buffer overflow.
Oracle released security updates for Oracle Linux 10, addressing multiple CVEs and including new kernel versions and enhancements alongside changes in driver signing and module handling.