[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> How the famed USENIX Security conf is managing a flood of papers in the AI era
AI usage is evident but isn't yet a serious problem
> OpenAI rolls out a major ChatGPT upgrade, even if you don’t pay for it
OpenAI is rolling out a more reliable version of ChatGPT GPT-5.6 Sol for Plus and Pro users, while Free users are getting unlimited text chats with GPT-5.6 Luna. [...]
> ClickFix attack pushes macOS infostealer for crypto theft attacks
A Go-based malware delivered in ClickFix attacks targeting macOS users is stealing cryptocurrency assets, browser-stored passwords, Apple Keychain data, and cached credentials. [...]
> ChainDrop: Inside a Self-Propagating npm Worm
Analysis of ChainDrop, an npm supply chain worm extracting GitHub Actions runner secrets and using Ethereum smart contracts for C2 routing. The post ChainDrop: Inside a Self-Propagating npm Worm appeared first on Unit 42.
> When Agentic Glue Melts: Exploiting Cloudflare Code Mode and Workers
By Yarden Porat, Check Point Research Key Points The short version We set out to break Cloudflare Code Mode, and ended up breaking Cloudflare Workers too. We did both by targeting workerd, the runtime beneath both: an in-process sandbox that relies entirely on V8 to isolate untrusted code. We found...
> Automate certificates with ACME support in AWS Certificate Manager
Customers tell us that managing TLS certificates at scale is one of their biggest operational concerns. The Certification Authority Browser Forum (CA/Browser Forum) has mandated a phased reduction in maximum certificate validity for public certificates. By March 2027, the maximum validity drops to 1...
> Why exposure management is replacing vulnerability management
Vulnerability management isn’t failing because security teams lack visibility. Most organizations already have more findings than they can reasonably address. Yet despite all those findings, many CISOs still struggle to answer a deceptively simple question: Are we actually bec...
> Hackers Stalked Me by Hijacking a Smartwatch for Kids
Security researchers tracked and eavesdropped on a WIRED reporter using vulnerabilities in a pink plastic smartwatch. It’s just one piece of a deeply insecure supply chain of GPS-enabled gadgets.
> Capitol Hill wants to know if executive branch, foreign allies coordinated enough to combat scams
A Senate Foreign Relations Committee hearing explored how 13 federal agencies and myriad foreign governments are wrestling with the problem. The post Capitol Hill wants to know if executive branch, foreign allies coordinated enough to combat scams appeared first on CyberScoop.
> Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group
A recent wave of cyberattacks targeting hedge funds, private-equity firms, and other financial organizations has been linked to UNC6671, an extortion group reportedly associated with the BlackFile campaign extortion group. [...]
> Google says hackers are calling financial firm employees to hack and extort victims
Groups of hackers are breaking into large U.S. financial firms to steal sensitive data and extort victims, Google’s security researchers report.
> China-linked LightSpy spyware caught targeting victims in 13 countries, including the US
Researchers linked the latest malicious activity to a Chinese company, after one of the spyware's operators placed an order with KFC using their real name and office address.
> Despite federal warnings, thousands of U.S. industrial controllers used in water systems remain exposed online
A scan of internet-connected industrial equipment found 4,400 exposed PLCs, including 22 in cities recently targeted by water system attacks. The post Despite federal warnings, thousands of U.S. industrial controllers used in water systems remain exposed online appeared first on CyberScoop.
> Oracle Linux 10 ELSA-2026-27288 Important Kernel Bug Fix
Oracle Linux has released security updates for kernel 6.12.0-211.34.1, addressing multiple vulnerabilities and enhancing driver signing, with various RPM packages available for x86_64 and aarch64 architectures.
> Oracle Linux freerdp Important Security Update ELSA-2026-50747
Oracle Linux has released RPM updates for version 10, resolving CVE-2026-55827 by adding codecID checks and fixing boundary checks in gdi_Bitmap_Decompress.
> AI struggles to patch vulns without adult supervision
Left alone, autonomous fixes often fail to fully remediate flaws
> Oracle Linux 9 osbuild-composer Important Security Patch ELSA-2026-22714
Oracle has released updated RPMs for Oracle Linux 9 addressing several CVEs, including significant enhancements in osbuild-composer and its components for both x86_64 and aarch64 architectures.
> Oracle Linux 9 Kernel Low Severity Bug Fix Advisory ELSA-2026-49870
Oracle Linux 9 has received an update with kernel and related RPMs addressing security issues, including CVE-2025-68214, and introduces changes to UKI signing and trusted keys.
> Route Amazon Bedrock Guardrails interventions to Amazon Security Lake
Security teams investigating AI-related incidents need guardrail intervention data alongside their existing security telemetry. Routing Amazon Bedrock Guardrails violations to Amazon Security Lake makes this possible. With this integration, you can query guardrail events alongside identity, network,...
> Oracle 9 gimp Important Fixes for CVE-2026-42169 and More ELSA-2026-50817
Oracle Linux has released an update for GIMP addressing multiple CVEs, available for both x86_64 and aarch64 architectures, as part of their security advisory ELSA-2026-50817.