[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> Unlimited Technology Systems breach impacts 3.8 million people
Healthcare software company Unlimited Technology Systems reported that more than 3.8 million people were impacted by a data breach incident that occurred in October 2025. [...]
> Debian Thunderbird Significant Code Execution Vulnerabilities DSA-6418-1
Debian has released Security Advisory DSA-6418-1 addressing multiple vulnerabilities in Thunderbird that may allow arbitrary code execution; users are urged to upgrade to version 1:140.13.0esr-2~deb13u1.
> Water utilities group partners with DEF CON offshoot for Water Watch Center
The National Rural Water Association and a group of cybersecurity experts have formed a program to help cash-strapped utilities face the increase in threats to their systems.
> Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer
A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platform malware targeting Windows, Mac, and Linux systems. "These packages appear to use AI slop squatted, or randomly generated typo-squatting package names, but a...
> Upgrading How You Sign In to Your Sucuri Account
Starting August 10, 2026, Sucuri will begin moving customer account logins to a new authentication platform designed to provide a stronger, more modern sign-in experience. The rollout will happen gradually over the following few weeks, so not every account will transition at the same time. For most...
> ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets
ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and cached credentials. The macOS-focused infection chain is designed to deliver a shell script that profiles the host and...
> UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data
A recent wave of cyber attacks targeting financial services, private equity, and professional services is attributed to a data extortion group known as UNC6671. "UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT help desk staff facilitating mandatory...
> US cyber ambassador nominee Cassady confirmed in Senate
NTIA official Adam Cassady becomes the second person confirmed to be the State Department's ambassador-at-large for cyber policy.
> Trojanized AI skills gain 1.7M installs in agent-targeted attack
Researchers have uncovered an extremely effective attack campaign that involved AI agent skills trojanized to deploy a credential stealer. The incident is part of a growing trend in which attackers are targeting the AI software supply chain by poisoning sharable instruction an...
> UODO - autorité polonaise
L'autorité polonaise de protection des données (UODO) a émis des objections concernant un projet de révision de la loi sur les fondations familiales, qui prévoit de rendre publiques sur internet les données personnelles des personnes qui y sont associées.Le président de l'UODO a exprimé de sérieuses...
> GPDP - autorité italienne
L'autorité italienne a sanctionné une société de production audiovisuelle pour l'utilisation de l'hypertrucage (« deepfake ») à des fins satiriques, jugeant que le réalisme des vidéos et l'insuffisance des avertissements violaient les principes de loyauté et de transparence, ainsi que l'obligation d...
> Debian libheif Critical Denial of Service and Code Execution DSA-6417-1
Debian announced multiple vulnerabilities in libheif that could lead to denial of service, sensitive information disclosure, or arbitrary code execution from malformed image files, advising updates to version 1.19.8-1+deb13u1.
> AEPD - autorité espagnole
L'autorité espagnole de protection des données a déclaré une violation du principe de confidentialité à l'encontre d'une municipalité pour avoir affiché un document administratif contenant des données personnelles sur un poteau, le rendant ainsi accessible au public. En application du droit national...
> AEPD - autorité espagnole
L'Agence Espagnole de Protection des Données sanctionne un éditeur de site web pour le dépôt de témoins de connexion avant tout consentement et pour avoir conditionné le refus à la souscription d'un abonnement payant.Faits et contexteL'Agence Espagnole de Protection des Données (AEPD) a aujourd'hui...
> More than half of AI-generated patches are broken
Research finds your AI generated security patch is more likely to fail than fully fix a vulnerability. It might even introduce brand new flaws to exploit along the way. The post More than half of AI-generated patches are broken appeared first on CyberScoop.
> New Mexico judge orders Meta to pay $567 million in kids online safety case
The money will be used to create a fund to mitigate social media harms, including by carving out $420 million for treatment for New Mexico youth who have been hurt on the platforms.
> Military device manufacturer discloses cyber incident to SEC
IEH Corporation — which produces specialized products used in military satellites, missiles and fighter jets — said it discovered a cyberattack on Tuesday and immediately tried to contain it.
> WordPress XSS2Shell Flaw Turns Simple Login Bug Into Full Server Takeover
WordPress XSS2Shell flaw enables admin takeover and remote code execution. Users should update to patched versions. Researchers at Pwn just published a report on a vulnerability chain they’re calling XSS2Shell, and the entry point is quite simple: type a username that doesn’t exist, and WordPress ec...
> Securing your Amazon S3 buckets: Identifying and remediating over-permissioned access
Misconfigured Amazon Simple Storage Service (Amazon S3) buckets can expose your data to unauthorized access. Without proactive review, S3 bucket policies or Access Control Lists (ACLs) configured with broad access may go unnoticed in your environment. In this post, you learn how to identify and fix...
> Ransomware attacks spike as world distracted by AI
What, you didn't think the top gangs were busy watching agents escape their sandboxes too, did you?