[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> NatJack exploits put NAT security assumptions to the test at Black Hat
For decades, Network Address Translation (NAT) has been the default way IP addresses are provided inside larger networks, as a means to deal with the challenges of IPv4 address availability. The basic premise behind NAT is that private addresses stay private, but that assum...
> Swiss government SharePoint breach compromised 200 accounts
Switzerland's federal IT office says hackers exploited vulnerabilities to breach its Microsoft SharePoint servers and compromised approximately 200 accounts. [...]
> Ransom Cartel creator sentenced to 16 years in prison
Maksim Silnikau participated in cybercrime since at least 2005. He ran Ransom Cartel from 2021 until his arrest in 2023. The post Ransom Cartel creator sentenced to 16 years in prison appeared first on CyberScoop.
> New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes
Researchers found a way to bypass recent mitigations for Spectre v2 speculative execution side-channel attacks and developed an exploit to leak secrets from Linux machines. [...]
> Why metaphor may dictate your security strategy
In this week's newsletter, Martin looks at how the metaphors we use to describe AI "escaping" its sandbox can completely change how we react to the threat.
> Debian Linux 6.12.101-1 Advisory DSA-6415-1 CVEs 2025-40098 to 2026-64584
Debian has addressed multiple vulnerabilities in the Linux kernel, which could cause privilege escalation, denial of service, or information leaks, advising users to upgrade their packages.
> New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts
Zapscape, a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM isolation and execute code on the host. The risk applies when nested virtualization is exposed to untrusted guests. The flaw is tracked as CVE-2026-64561 ...
> Photos: Black Hat USA 2026, part two
Round two from Black Hat USA 2026. This set covers the parts of the show floor that did not make the first gallery. Scroll through below. Featured vendors: BlackCloak, Teleport, GitGuardian, Oak, Hexnode, Picus Security, Featured speaker: Kate Silverstein (Mozilla) discussing crowd-sourcing protecti...
> Cyberattack on North Carolina Ports ‘contained’ as Coast Guard, state officials investigate
North Carolina Ports is recovering from a cyberattack after its IT system was “hacked by an outside actor or group,” requiring a switch to manual processing of operations.
> Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.8 CVSS Score Bugs
Cisco has rolled out updates to address multiple critical security vulnerabilities impacting Catalyst SD-WAN and IOS XE Software as part of a comprehensive internal security review. The security issues affect Cisco Catalyst SD-WAN Software, regardless of device configuration, and Cisco IOS XE Softw...
> Canadian Man Pleads Guilty in Snowflake Extortions
A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud data storage provider Snowflake. Connor Riley Moucka, of Kitchener, Ontar...
> Humans in the loop miss a third of dangerous AI coding agent requests
You wouldn't let Claude Code cat your AWS credentials or Kubernetes config on request, would you?
> Exposed SISVISA Database Leaks 102,000 Brazilian Health Surveillance Records
An exposed SISVISA database leaked 102,215 Brazilian health records, exposing IDs, tax data, and regulatory documents without authentication. Researcher Jeremiah Fowler found a publicly accessible database that turned out to belong to SISVISA, Brazil’s Health Surveillance Information System, and ale...
> Hacker pleads guilty to stealing data from more than 165 Snowflake customers
Connor Moucka pled guilty to hacking and stealing data from more than 165 Snowflake customers, which net him and his accomplices more than $2.5 million in ransom payments.
> Debian UDisks2 Important Local Privilege Escalation CVE-2026-7867
A local privilege escalation vulnerability in udisks2 (CVE-2026-7867) allows unprivileged users to influence mount execution paths, necessitating an upgrade to version 2.10.1-12.1+deb13u2.
> Vishing attacks: How businesses can defend against voice phishing
Learn what vishing is, why AI voice cloning makes voice phishing harder to spot, and get vishing attack prevention tips for your business.
> AEPD - autorité espagnole
L'autorité espagnole de protection des données (AEPD) a publié une décision de classement d'une plainte contre Meta Platforms Ireland Limited, concernant l'utilisation de données personnelles pour l'entraînement de modèles d'intelligence artificielle. La plainte a été rejetée car l'entreprise a volo...
> ANSPDCP - autorité roumaine
Sanction pour un défaut de gouvernance interne ayant permis un accès non autorisé à des données, une collecte excessive de données sensibles, un manquement à l'information et des communications commerciales illicites.Faits et contexteL'Autorité Nationale de Surveillance du Traitement des Données à C...
> New Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUs
An unprivileged Linux program can time a hardware interrupt to land in the gap between a processor sanitizing its branch predictor and the kernel using it, re-poisoning the predictor after the defense has run. MIT CSAIL researchers Daniël Trujillo and Mengjia Yan named the technique INTERRUPT INJEC...
> Caching KMS data keys in multi-thread environments: Per-tenant encryption for event-driven systems at scale
This post assumes familiarity with envelope encryption and the AWS Encryption SDK. When your encryption system generates millions of duplicate API calls per hour, costs spiral and performance degrades. That’s exactly the challenge NICE Actimize faced while operating their global-scale, event-driven...