[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> Cyberattack on Steam hardware shipper leaks names, addresses, and order data
Video game publisher Valve is alerting customers in Europe to a data breach at CEVA Logistics, its Steam hardware shipping partner. Reports from affected customers began surfacing on social media earlier today, after Valve started sending out data breach notification emails. “Between July 29 2026 an...
> CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs
CISA has confirmed that ransomware gangs have begun exploiting two recently patched SonicWall SMA1000 vulnerabilities, including a maximum-severity server-side request forgery (SSRF) flaw. [...]
> OpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack Concerns
The current GPT-5.6-Sol has been assigned a ‘high’ cybersecurity threshold, but Astra could reach the maximum ‘critical’ threshold.  The post OpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack Concerns appeared first on SecurityWeek.
> WordPress Plugins Compromised Without a Single File Change
Poisoned JSON feed let attackers backdoor WordPress sites without changing any plugin files
> Why transparent AI agents matter more than you think
The difference between a prompt injection attack you'll catch and one you won't might just be whether your AI agent can explain itself. The post Why transparent AI agents matter more than you think appeared first on CyberScoop.
> A data breach at shipping giant Ceva Logistics is rippling across banks, retailers, Steam gamers, and beyond
Companies that rely on Ceva Logistics for shipping their physical goods to customers say their personal data was taken during a recent cyberattack.
> Stealthium Targets Security Blind Spots in AI Accelerators and Neo-Clouds
The startup analyzes subtle telemetry signals to detect attacks that traditional security tools cannot see inside accelerator-powered AI infrastructure. The post Stealthium Targets Security Blind Spots in AI Accelerators and Neo-Clouds appeared first on SecurityWeek.
> Signed up for Klaviyo? Dozens of advertisers may have seen your password
A bug in the tech giant's website mistakenly shared users' sign-up information, including personal data and their password, to third-party companies.
> Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC
Remote, unauthenticated attackers could exploit the bugs to cause a denial-of-service (DoS) condition. The post Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC appeared first on SecurityWeek.
> When Credentials Are No Longer Enough: Device Trust in the AI Era
AI is making phishing, credential theft, and social engineering faster and more efficient, while traditional trust signals such as passwords, MFA, IP reputation, and geolocation become easier to bypass. Specops explains why organizations are increasingly adding device trust to their Zero Trust strat...
> CVE-2021-36946 Microsoft Dynamics Business Central Cross-site Scripting Vulnerability
Updated the build numbers. This is an informational update only.
> CVE-2024-38225 Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
Updated the build numbers. This is an informational update only.
> 10th August – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 10th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES North Carolina Ports, the US authority operating the ports of Wilmington, Morehead City and others, has suffered a cyberattack that forced some operati...
> CVE-2021-40440 Microsoft Dynamics Business Central Cross-site Scripting Vulnerability
Updated the build numbers. This is an informational update only.
> CVE-2021-34474 Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability
Updated the build numbers. This is an informational update only.
> USN-8626-1: systemd vulnerabilities
It was discovered that systemd-homed did not properly verify the signature of home records. A local attacker could possibly use this issue to add arbitrary system groups to a logged-in user and gain elevated privileges. (CVE-2026-16742) It was discovered that systemd-machined incorrectly handled ce...
> CVE-2024-21380 Microsoft Dynamics Business Central/NAV Information Disclosure Vulnerability
Updated the build numbers. This is an informational update only.
> CVE-2025-29821 Microsoft Dynamics Business Central Information Disclosure Vulnerability
Updated the build numbers. This is an informational update only.
> British ‘Com’ member who abused more than 100 girls worldwide jailed for two years
Justin Swaddle, of Leeds in northern England, targeted 117 female victims aged 13 to 17, according to the National Crime Agency.
> Metabase zero-day exploited to access Framework customer data
Framework, the San Francisco-based company that designs repairable and upgradeable laptops, has suffered a data breach after attackers managed to exploit a zero-day vulnerability in the Metabase business intelligence service. According to the notification sent to affected Framework customers, the at...