[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild
A newly patched security flaw impacting on-premise versions of JetBrains TeamCity has come under active exploitation in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The vulnerability in question is CVE-2026-63077 (CVSS score: 9.8), a case of deserializati...
> Hackers Start Exploiting Recent JetBrains TeamCity Vulnerability
Tracked as CVE-2026-63077, the critical bug can be exploited without authentication for remote code execution. The post Hackers Start Exploiting Recent JetBrains TeamCity Vulnerability appeared first on SecurityWeek.
> Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People
Connor Riley Moucka pleaded guilty in Seattle federal court on Wednesday to computer fraud, wire fraud, aggravated identity theft and a related conspiracy over the 2024 breaches of Snowflake customer accounts. The intrusions reached at least 165 organizations and exposed records belonging to at lea...
> OWASP 2026 LLM Top 10: “The model will be fooled”
The OWASP GenAI Security Project has released the 2026 edition of its Top 10 for LLM Applications and, for the first time, the list was influenced by real-world incidents. The two top entries – Prompt Injection and Sensitive Information Disclosure – remained constant, but the order shifted more than...
> Snowflake Hacker Pleads Guilty After Breaching 165 Companies and Stealing Billions of Records
Snowflake hacker Connor Moucka pleads guilty after breaching 165 organizations, stealing billions of records, and extorting victims. Connor Riley Moucka, 26, of Kitchener, Ontario, pleaded guilty this week to a computer hacking conspiracy that compromised over 165 organizations, stole billions of cu...
> Browser security is where software, data, and AI meet
In this interview with Help Net Security, Rui Ribeiro, CEO of Jscrambler, explains why the browser has become a security problem organizations do not control. Companies do not own the device, the extensions, or the network path, yet that is where application logic, third-party code, customer data, a...
> Expanding AI Benchmarks in Cybersecurity Beyond Vulnerability Discovery
> Suppliers, logins, and AI tools are all becoming attack paths
Cybercriminals and state-backed hacking groups are abusing trusted identities, cloud services, AI tools, and software supply chains to gain access while avoiding detection, according to CrowdStrike’s 2026 Threat Hunting Report. Intrusion activity increased by about 4% over the past year. Even though...
> Chinese router vendor denies its firmware contains backdoors – but pauses downloads to fix security issues anyway
It’s just a remote maintenance function, says Zbtlink
> Non-human identities are 91% of everything active in production
A backup job fires at two in the morning. A scanner walks the same AWS account an hour later, a deployment pipeline assumes a role at four, and a logging agent runs straight through the night. Each of those actions carries a credential issued to a machine. An attacker holding one of those credential...
> Cloudflare OS goes open source with a record of everything its agents read
Cloudflare open sourced Cloudflare OS, the agent platform whose first version its own employees have used since May. Every resource an agent reads gets recorded, the record follows whatever the agent produces, and when a second person opens that output the platform checks them against the underlying...
> State Department says Trump raised cyber scam compound issue with Xi
President Donald Trump has talked with Chinese President Xi Jinping about Southeast Asian scam compounds, a State Department official told senators at a hearing on the transnational issue.
> Republic of Georgia alleges foreign disinfo campaign sought to scare off Russian tourists
Georgia's State Security Service is investigating whether foreign entities were behind the spread of fabricated stories claiming that Georgians were mistreating Russian tourists.
> mkcert : créer des certificats HTTPS valides en local sur Debian
Guide pratique mkcert sur Debian : créez votre autorité de certification locale et générez des certificats HTTPS reconnus par vos navigateurs. Le post mkcert : créer des certificats HTTPS valides en local sur Debian a été publié sur IT-Connect.
> ISC Stormcast For Thursday, August 6th, 2026 https://isc.sans.edu/podcastdetail/10040, (Thu, Aug 6th)
> OpenAI reveals its rogue agent swarm went a little bit Borg ahead of Hugging Face hack
It started with an 'impossible task' and led to AI deciding it needed to act as a collective intelligence
> OpenAI Didn’t Notice Its AI Agents Using a Message Board to Plan Their Hacking Spree
At the Black Hat security conference, the AI giant revealed new details about how its agents went rogue, hacked several other companies—and did it all right under the company’s nose.
> 22 Seconds to Compromise: How Automated SSH Actors Move From Login to Persistence Before You Can Blink [Guest Diary], (Thu, Aug 6th)
[This is a Guest Diary by Daryl Jiminez, an ISC intern as part of the SANS.edu BACS program]
> Lancaster
La ville de Lancaster, Ohio, a dû mettre hors ligne ses ordinateurs municipaux le 6 août suite à des alertes de rançongiciel sur plusieurs machines. Bien que les systèmes essentiels (911, eau, etc.) n'aient pas été directement affectés, l'incident a entraîné des perturbations. Le 28 août, un comité...
> Ambition DX Holdings
Ambition DX Holdings a été victime d'un accès non autorisé à son serveur de fichiers, entraînant la confirmation d'une fuite de certaines informations. Les données potentiellement compromises incluent des informations personnelles (noms, adresses, numéros de téléphone, adresses e-mail) de clients, d...