[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (112 articles)

|

// AI-powered summary generated at 20:00

> NATO and an AI startup can now name and track software vulnerabilities
NATO’s cyber defense arm and a startup that uses artificial intelligence to find software flaws can now issue the ID numbers the industry uses to track those flaws, the European Union Agency for Cybersecurity announced last week.  The NATO Cyber Security Centre, part of the NATO Communications and I...
> Meta’s Ray-Bans are being banned from pubs, restaurants, and theatres
A growing number of UK venues have decided to act against privacy-busting smart glasses. Read more in my article on the Hot for Security blog.
> FBI, South Korea warn of Gunra ransomware gang targeting critical infrastructure
The Gunra ransomware gang is breaching critical infrastructure organizations through vulnerabilities in popular brands of firewalls, the FBI and South Korea’s government warned.
> OpenAI releases ChatGPT 5.6 Cyber, but it's only for approved users
OpenAI has developed a new model called "GPT 5.6 Cyber," designed for vulnerability research, penetration testing, incident response, and remediation. [...]
> U.S., South Korean government agencies caution to be on lookout for Gunra ransomware gang
The ransomware-as-a-service outfit has gone after a range of critical infrastructure sectors across the globe. The post U.S., South Korean government agencies caution to be on lookout for Gunra ransomware gang appeared first on CyberScoop.
> Debian libyaml-syck-perl Important DoS and Code Exec Issues DSA-6428-1
Debian has released an advisory regarding vulnerabilities in libyaml-syck-perl, advising users to upgrade to version 1.34-2+deb13u3 to mitigate potential denial of service and code execution risks.
> Everything we launched during Agents Week
Our latest Agents Week has come to a close. Here’s a recap of all the announcements we made, from Wallets to Radar.
> New StormEncryptor ransomware used by former Medusa affiliate
A financially motivated threat actor previously associated with the Medusa ransomware operation is now deploying a new ransomware strain called StormEncryptor. [...]
> Debian Wordpress Critical Remote Code Execution Vulnerabilities DSA-6427-1
Debian released an advisory regarding multiple vulnerabilities in WordPress, including risks of cross-site scripting and remote code execution, urging users to upgrade to version 6.8.7.
> North Korean spies are running local LLMs to cause AI mischief
Kimsuky's phishing attacks get an AI boost
> Meta Must Stop Silencing Reproductive Health Information
Access to accurate information about reproductive and maternal health can be critical. But on Meta's platforms, simply talking about prescription medication, abortion care, or one's own medical experiences can be enough to trigger content removals and account restrictions. That's why EFF recently su...
> How to fake a data trail (and maybe lower prices) (Lock and Code S07E16)
This week on the Lock and Code podcast, we speak with Chris Parr about his inventive and all-too-funny stress-test of surveillance pricing.
> Understanding the FATF’s DeFi Report: A Functional Approach to Decentralized Finance Regulation
Summary The FATF just released its first DeFi-specific report: Acknowledging DeFi’s operational benefits, the global AML/CFT standard-setter explains how jurisdictions,… The post Understanding the FATF’s DeFi Report: A Functional Approach to Decentralized Finance Regulation appeared first on Chainal...
> 2026 AWS CyberVadis report now available for due diligence on third-party suppliers
We’re excited to announce that Amazon Web Services (AWS) has completed theCyberVadis assessment of its security posture with the highest score (Mature) in all assessed areas. This demonstrates our continued commitment to meet the heightened expectations for cloud service providers. Customers can now...
> data.europa.eu
Les institutions de l'Union européenne soulignent le rôle essentiel des données ouvertes, notamment celles du Portail européen de données, pour soutenir l'innovation en matière d'intelligence artificielle générative.L'intelligence artificielle générative, qui crée des contenus tels que du texte, des...
> CNIL
La Commission Nationale de l'Informatique et des Libertés (CNIL) a publié des recommandations visant à identifier et gérer les conflits d’intérêts pouvant survenir lorsque le délégué à la protection des données (DPO) exerce d’autres missions.Le RGPD autorise un DPO à exercer d’autres missions que ce...
> Gym rat asks AI agent to book him a class, it hacks a waitlist API to bump him up the list
What wouldst thou ask of the monkey's paw?
> UOOU - autorité tchèque
L'Office pour la protection des données personnelles tchèque (ÚOOÚ) a publié sa recommandation n° 1/2026 concernant l'utilisation de systèmes de vidéosurveillance par les prestataires de services de santé.Ce document a été élaboré pour répondre à des commentaires sur une méthodologie générale relati...
> AEPD - autorité espagnole
L'autorité espagnole de protection des données a sanctionné un opérateur de télécommunications pour avoir délivré un duplicata de carte SIM à un fraudeur, considérant que le manquement de l'agent du point de vente à appliquer correctement les procédures de vérification d'identité constituait un trai...
> China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw
Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called StormEncryptor. The use of StormEncryptor marks a shift from the adversary's previous use of Medusa ransomware, the Microsoft Threat Intelli...