[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> 4 million fake applications and one blind spot: A SOC playbook for OAuth client ID spoofing
Key takeaways OAuth client ID spoofing defeats detections that key off application name or a known application ID, because the field itself is fabricated, rotated or blank. AADSTS700016 paired with an unrecognized client ID can mean valid credentials, not a broken app r...
> Misconduct Or Mental Injury? A Question Policing Can No Longer Avoid
Can trauma show up as misconduct? Paul Gullon-Scott explores how cumulative trauma and organisational stress can shape behaviour in policing and digital forensics and why earlier, trauma-informed support could make all the difference.
> US Sanctions Iranian $6bn Crypto “Exchange” Shelbit
TRM Labs explains that sanctioned Iranian firm Shelbit was a fake crypto exchange
> Corporate Data Stolen in Levi Strauss Cyberattack
Using social engineering, a threat actor accessed the computers of three employees and exfiltrated data from them. The post Corporate Data Stolen in Levi Strauss Cyberattack appeared first on SecurityWeek.
> 7 key trends defining the cybersecurity market today
AI is having a seismic impact on the cybersecurity market. Record-shattering amounts of venture capital is flowing into a new generation of startups focused on AI cybersecurity. At the same time, established cybersecurity vendors are racing to integrate AI and agentic AI fe...
> A GitHub Misconfiguration Let Kimi K3 Cheat a Cybersecurity Benchmark
Kimi K3 bypassed a UK cybersecurity test by accessing GitHub, cloning the benchmark and reading its solutions instead of solving the challenge Sometimes the smartest move isn’t solving the puzzle, it’s noticing nobody locked the door to the answer key. That’s essentially what happened when Moonshot’...
> Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials
Cybersecurity researchers have flagged a malicious Microsoft Visual Studio Code (VS Code) extension named Solidity Pro ("solidity-pro") that has been observed delivering a browser wallet and credential stealer. The names of the extensions are below - helper-beeps.solidity-pro web3devtoolsx.so...
> OpenAI locks down Astra over potential critical cyber capabilities
OpenAI’s internal evaluation of its upcoming model, Astra, found significant advances in agentic coding and cybersecurity, leading the company to conclude that it cannot rule out the model reaching the critical capability level for cybersecurity under its Preparedness Framework. The Preparedness Fra...
> GitHub Dependabot malware alerts now cover eight ecosystems
GitHub has flagged npm malware since March 2026. Anyone pulling in a bad PyPI, Maven, RubyGems, NuGet, Go, crates.io, or PHP Composer package has had no such warning, because GitHub’s malware detection only ever watched one ecosystem. That changed this month. GitHub’s Advisory Database now ingests m...
> A week in security (August 3 – August 9)
A list of topics we covered in the week of August 3 to August 9 of 2026
> OpenAI's Next AI Model Astra Shows Cyber Performance Strong Enough to Trigger Pause
OpenAI has announced that it's pausing some "internal activities" involving its upcoming artificial intelligence (AI) model Astra after an internal evaluation found it had made significant advancements in agentic coding and cybersecurity. In response to the discovery, the AI upstart said it's imple...
> Chainloop: Open-source evidence store and policy engine for the software supply chain
Chainloop is an open source evidence store for the software supply chain. A command line tool runs inside a GitHub Actions, GitLab, Jenkins, or Dagger pipeline, picks up what the build produced, uploads those files to content-addressable storage, and references each one in a signed in-toto attestati...
> Product showcase: Enpass Password Manager breaks away from the proprietary cloud model
Enpass is a password manager that stores passwords, passkeys, payment cards, identities, secure notes, software licenses, and other sensitive information in encrypted vaults. Vaults remain on the device or in a cloud storage service selected by the user. Users who work across multiple devices can in...
> Critical Flaws Discovered in Belgian eID Software Used by 2 Million People
The vulnerabilities affected software used by eight of Belgium’s ten largest banks and over 60 government agencies. The post Critical Flaws Discovered in Belgian eID Software Used by 2 Million People appeared first on SecurityWeek.
> 71% of CISOs spend 10+ hours on board reports
Boards want evidence that security controls and architecture reduce business risk, expressed in terms of resilience, consequence, and decision relevance. Translating technical findings into business language remains a major time burden for CISOs, who are calling for simpler data delivery, better fra...
> How to report an AI Act violation in the EU
The EU’s fight to regulate AI models entered a new chapter on 2 August 2026, when the European Commission’s AI Office and national authorities began enforcing the AI Act. The AI Act is the EU’s law regulating AI, the first broad legal framework of its kind. It creates a common set of rules for AI sy...
> Advertisers are trying to influence AI bots with secret ads
PLUS: Hiveminds are emerging to hack the planet, and open-weight models are the new new red scare.
> ISC Stormcast For Monday, August 10th, 2026 https://isc.sans.edu/podcastdetail/10044, (Mon, Aug 10th)
> Delta School District
Le district scolaire de Delta a été victime d'un incident de cybersécurité affectant son environnement informatique DeltaLearns.ca. Le district a découvert l'incident le 10 août 2026, lorsque des activités non autorisées ont été détectées, rendant le site indisponible. Bien qu'il n'y ait pas de preu...
> Weba
Les pirates informatiques du groupe Qilin ont dérobé des données clients chez WEBA et ont partiellement paralysé ses systèmes. Aucune rançon n'a été versée ; les magasins et la boutique en ligne sont à nouveau opérationnels depuis le 12 août. Les clients doivent rester vigilants face aux tentatives...