[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> CVE-2026-64572 ipv4: fib: free fib_alias with kfree_rcu() on insert error path
Information published.
> CVE-2026-64542 ipv6: ndisc: fix NULL deref in accept_untracked_na()
Information published.
> Webmail CSS Attacks Expose a New Risk for AI-Powered Email Tools
CSS attacks on major webmail services can steal credentials, hijack sessions and manipulate AI tools connected to users’ inboxes. PortSwigger researcher Gareth Heyes demonstrated something that should make every webmail team a little nervous: plain CSS, the styling language that’s supposed to just m...
> CVE-2026-64560 posix-cpu-timers: Prevent UAF caused by non-leader exec() race
Information published.
> CVE-2026-64565 Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data()
Information published.
> Week in review: Cisco fixes IMC bug, Patch Tuesday forecast, Black Hat USA 2026
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Mapping the malware blast radius a single alert won’t show you In this interview with Help Net Security, Mike Wiacek, founder and CTO of Stairwell, explains Backstory, an AI agent that takes a single al...
> CVE-2026-64562 KVM: nVMX: Hide shadow VMCS right after VMCLEAR
Information published.
> CVE-2026-64564 sctp: don't free the ASCONF's own transport in DEL-IP processing
Information published.
> Cyber actualités ZATAZ de la semaine du 3 au 9 août 2026
Bonjour à toutes et tous Cette semaine, ZATAZ découvre 1,7 milliard d’identifiants français uniques stockés dans un cloud pirate, tandis que 43 revendications de rançongiciels ciblent la France en un mois. Qilin menace de publier des données du Stade français et expose déjà des pièces d’identité. Cu...
> CVE-2026-64561 KVM: x86: Check for invalid/obsolete root *after* making MMU pages available
Information published.
> CVE-2026-62994 CoreDNS `k8s_external` headless AXFR can emit an empty transfer batch that panics the `transfer` plugin
Information published.
> Debian Chromium Critical Code Exec Denial of Service Advisories DSA-6422-1
Debian's security advisory DSA-6422-1 reports multiple vulnerabilities in Chromium that may lead to code execution, denial of service, or information disclosure, recommending users update to the latest version.
> CVE-2026-63263 Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service
Information published.
> CVE-2026-44605 Rpm: heap buffer overflow in ndb slot table parsing
Information published.
> Sakura
Sakura confirmé une intrusion par un tiers dans une partie de ses serveurs de location ('Sakura Rental Server'). L'incident, survenu le 9 août 2026, impliquait l'accès non autorisé à environ 583 comptes. Il a été confirmé que des données personnelles, y compris des informations clients, ont pu être...
> CVE-2026-71227 Libkcapi: infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandled io_getevents() timeout return
Information published.
> CVE-2026-71226 Libkcapi: memory corruption via uncanceled aio requests on error in libkcapi's one-shot aio path
Information published.
> Itaguaí Construções Navais (ICN)
L'Itaguaí Construções Navais (ICN) a été victime d'une cyberattaque par ransomware qui a touché ses systèmes informatiques, y compris les serveurs de messagerie, les systèmes de fichiers et les bases de données. L'attaque a été détectée le dimanche soir (9) et a entraîné la cryptographie des données...
> CVE-2026-71225 Libkcapi: iv reuse in libkcapi one-shot symmetric cipher chunking causes cipher state reset across chunk boundaries
Information published.
> CVE-2026-54876 Client-Side Memory Leak in OCSP Response Checking
Information published.