[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> Ransom Cartel ransomware creator sentenced to 16 years in prison
Maksim Silnikau, the creator and administrator of the Ransom Cartel ransomware operation, was sentenced to 16 years in prison for his role in ransomware attacks against at least 18 companies worldwide. [...]
> Security validation should begin where attackers begin
Modern attacks increasingly begin with the web application. Customer portals, partner platforms, APIs, external business applications, and AI-powered services have become the front door to the enterprise. The systems organizations build to create value are now the same syst...
> Canadian pleads guilty to Snowflake cloud data-theft attacks
A Canadian man pleaded guilty today to his role in accessing company accounts at cloud storage provider Snowflake and stealing data from at least 165 organizations in a scheme to extort millions of dollars from victims. [...]
> Oracle Thunderbird Significant Revision ELSA-2026-49922
Oracle Linux 8 has updated Thunderbird package versions to address multiple CVEs, which include security fixes and configuration changes, available for both x86_64 and aarch64 architectures.
> Oracle 8 fence agents Advisory ELSA-2026-49927 for CVE-2026-44431
Oracle Linux 8 has released updated RPMs for various fence agents to fix CVE-2026-44431, improving security and addressing identified vulnerabilities.
> Why security validation must follow the attack path
For years organizations have strengthened their security posture by investing in specialized tools for applications, identities, endpoints, networks, and cloud infrastructure. Those investments remain essential, but the way attackers operate has changed dramatically. Today’s a...
> Oracle Linux 7 Kernel Important Security Update ELSA-2026-500121
Oracle Linux 7 has received kernel updates addressing multiple security vulnerabilities, including fixes for KVM-related issues and XFS data handling, along with updates for NIC and net scheduling.
> Oracle mingw-glib2 Important Buffer Overflow Issues ELSA-2026-49512
Oracle Linux 8 updates include fixes for multiple CVEs related to glib2 packages, addressing various vulnerabilities such as buffer overflows and integer overflows to enhance system security.
> Prompt injection isn't the bug, AI agent frameworks are
Check Point researchers tried to break the frameworks enterprises use to build AI apps. Now they're telling Black Hat attendees what they found
> Oracle ELSA-2026-49520 ldns Important DNS Source Validation Issue
Oracle Linux 8 has received updates to the ldns package, addressing CVE-2026-10846 by improving DNS response validation and including several related rpm versions for various architectures.
> Snowflake hacker pleads guilty, faces up to 32 years in prison
Connor Moucka obtained almost $500,000 for playing a key role in one of the most widespread and damaging cyberattack sprees on record. The post Snowflake hacker pleads guilty, faces up to 32 years in prison appeared first on CyberScoop.
> AWS partners with Anthropic and OpenAI to bring AWS Continuum into developer workflows
Customers have access to models that are continuously getting better with each new generation bringing larger context windows, stronger reasoning, and lower token costs. Getting the strongest AI-powered security will come from tools that combine the most relevant models with deep knowledge of a cust...
> Chinese telcos maintain deep US presence despite Salt Typhoon links, House committee says
Three Chinese telecommunications giants continue to have footholds in the U.S. internet ecosystem despite their alleged role in previous Chinese hacking campaigns, a House committee report concluded.
> DHS Wants Protesters’ Signal Group Chats
A lawsuit accuses Homeland Security of violating protesters’ free-speech rights—but the agency is using it to try to get access to the plaintiffs’ encrypted communications.
> Canadian man pleads guilty to Snowflake hacks that led to 165 breaches
A 26-year-old from Ontario faces as many as 32 years in prison after pleading guilty to fraud, identity theft and conspiracy charges related to the 2024 hacks of cloud platform Snowflake.
> Hackers run khunt post-exploitation toolkit from Oracle database
Hackers exploited a SQL injection vulnerability to install a post-exploitation toolkit directly inside an Oracle database that was used to breach a corporate network. [...]
> Why human error is your biggest cybersecurity risk — and how to reduce it
Learn why human error is a major cybersecurity risk for businesses and how better systems and safer defaults can reduce employee mistakes.
> The Most Dangerous AI Hacking Techniques Still Have Humans in the Loop
Security researcher James Kettle tried to push the limit of AI’s hacking abilities—and discovered how effective it can be when combined with human expertise.
> How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones 
The chain involved the exploitation of several vulnerabilities in the Samsung Members and Samsung Account applications. The post How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones  appeared first on SecurityWeek.
> AI Deception Emerges in Cyber Tests as Agents Target Real People and Systems
AISI found AI agents taking unsanctioned online actions, including social engineering and code attacks, during controlled cyber tests. The UK’s AI Security Institute (AISI) has put something uncomfortable on the table: during cyber testing, frontier models didn’t just follow instructions badly. In s...