[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (112 articles)

|

// AI-powered summary generated at 20:00

> Oracle Linux 10 ELSA-2026-51295 Kernel Moderate Bug Fix CVE-2026-43186
Oracle Linux has released security updates for version 10, addressing various fixes and CVE-2026-43186, including kernel enhancements and certificate updates, available on the Unbreakable Linux Network.
> Oracle Linux 10 libarchive Moderate Security Advisory ELSA-2026-52675
Oracle Linux has released updates for version 10, addressing security vulnerabilities related to CVE-2026-14164 with new rpm packages available for both x86_64 and aarch64 architectures.
> Cars.no : une fuite revendiquée expose 148 288 automobilistes
Cars.no aurait exposé noms, téléphones et plaques, créant un risque élevé de phishing automobile ciblé.
> Oracle Linux 10 nodejs-nodemon Important Security Fix ELSA-2026-52841
Oracle Linux updated the nodejs-nodemon package for version 10 to address CVE-2026-69152, related to brace-expansion fixes, available for x86_64 and aarch64 architectures.
> Des kiosques Pokémon exposés par une fuite Firebase
Une fuite Firebase présumée expose kiosques Pokémon, paiements, code source et accès à 217 machines connectées.
> Un phishing Ameli qui observe avant de frapper
Phishing Ameli, cloaking et fausse boutique IA : le clic pourrait servir Ă  identifier et qualifier de futures victimes.
> The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications
Analysis of the Aeternum botnet loader, a threat leveraging Polygon blockchain smart contracts for decentralized C2 infrastructure and payload execution. The post The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications appeared first on Unit 42.
> Une fausse lettre AR24 vole les identifiants mail
Nouveau faux mail AR24, CAPTCHA et vol d’identifiants : Tester en live ce phishing et vérifier une notification AR24.
> Ubuntu ImageMagick Heap Overflow and Code Execution Security Flaws
Ubuntu has patched several vulnerabilities in ImageMagick across various LTS versions, which could allow for arbitrary code execution and denial of service through specific image handling flaws.
> GPDP - autorité italienne
Une municipalité italienne a été sanctionnée pour avoir communiqué prématurément l'appartenance syndicale d'une employée à son futur employeur, l'autorité jugeant que la finalisation future du transfert de l'employée ne justifiait pas une telle divulgation anticipée en l'absence de base juridique sp...
> GPDP - autorité italienne
La publication d'une décision administrative mentionnant le numéro de matricule et le motif de la rupture du contrat de travail d'un agent public, même en l'absence de son nom, constitue une diffusion illicite de données personnelles, car l'agent reste identifiable par le contexte.Faits et contexteL...
> The FTC wants to regulate AI for ideological bias 
The commission is mulling whether to begin regulating bias in AI systems. Critics say they’re overstepping their legal authority and infringing on free speech. The post The FTC wants to regulate AI for ideological bias  appeared first on CyberScoop.
> Gym Booking Task Turns Into Real-World AI Cyberattack
An AI agent hacked a gym booking system while trying to help a user, booking early and removing another person from the waitlist. An Australian man asked his AI assistant to book him into a gym class. He didn’t ask it to hack the booking software, and he definitely didn’t ask it to remove another […...
> BdThemes plugins supply-chain hack creates rogue WordPress admins
A threat actor compromised the upstream infrastructure of BdThemes, a developer of premium WordPress web-design tools, and modified a remote JSON feed delivered to administrators' browsers to create rogue admin accounts. [...]
> DEF CON hackers add new muscle to water utility protection
Franklin project adds new security providers, employs digital twins and AI
> OpenAI says Daybreak will expand to offer specialized cyber services 
The company rolled out “Red” and “Blue” programs for defenders, introduced a new model and announced partnerships with 16 major cybersecurity vendors. The post OpenAI says Daybreak will expand to offer specialized cyber services  appeared first on CyberScoop.
> Une nouvelle fuite pour la FF Handball ?
Un pirate revendique 1,3 million de lignes volées à la FF Handball après plusieurs publications visant des groupes français.
> À vendre : les coulisses d’un empire du pari
Un vendeur du dark web propose accès casino, bases de joueurs et données crypto dans un catalogue spécialisé.
> AWS completes the 2026 Police-Assured Secure Facilities (PASF) audit in Europe (London)
We’re excited to announce that our Europe (London) AWS Region has renewed its accreditation for United Kingdom (UK) Police-Assured Secure Facilities (PASF) for Official-Sensitive data. Since 2017, the Amazon Web Services (AWS) Europe (London) Region has been accredited under the PASF program. This d...
> USN-8592-1: ImageMagick vulnerabilities
Hao Ren discovered that ImageMagick incorrectly handled certain images when using the wavelet-denoise operation. An attacker could possibly use this issue to trigger an out-of-bounds heap write, resulting in arbitrary code execution. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubunt...