[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> 7 privacy gadgets a Proton employee actually uses
From kill cords to Faraday pouches, here are the physical privacy tools you can use when a password alone isn't enough.
> Tom Cotton prods Treasury for tax code tweaks to modernize OT
The Senate Intel Committee chair wrote to Treasury Secretary Scott Bessent about changes to spur investment in aging technology to better guard against cyberattacks. The post Tom Cotton prods Treasury for tax code tweaks to modernize OT appeared first on CyberScoop.
> Apple’s iCloud Private Relay is leaking the IP addresses it’s supposed to hide
Researchers found a flaw in Apple's iCloud Private Relay that exposes real IP addresses, the second iCloud privacy failure this summer.
> Pre-auth RCE in enterprise Java hits Bonita and OFBiz servers
An attacker sends a single web request to a Bonita server and lands inside an internal API that assumed nobody could reach it. The request arrives unauthenticated. From there the attacker runs code on the host. Bonita BPM handles loan approvals, insurance claims, and employee onboarding for banks, i...
> Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures
A macOS ClickFix operation spanning more than 250 front-end domains now fingerprints visitors before deciding whether to show them a malware lure, a change Microsoft Threat Intelligence tracked on infrastructure it had been watching for weeks. The server-side gate hides the malicious page from craw...
> OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes
OpenAI said it disrupted a Cambodia-based scam operation that used its generative artificial intelligence (AI) chatbot ChatGPT to facilitate a wide range of investment, romance, gambling, and law enforcement impersonation schemes. To that end, it banned a coordinated network of ChatGPT accounts lik...
> Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm, (Wed, Aug 5th)
When you learn that a compromised package executed on one of your build hosts, muscle memory takes over: revoke the npm token, rotate the GitHub PAT, cycle the cloud keys. That reflex has been correct in almost every supply-chain incident I have worked. In the keyv/cacheable compromise that has been...
> COLDCARD security audit phishing attack installs remote access tool
A phishing campaign is exploiting fears surrounding the recently disclosed COLDCARD wallet vulnerability and suspected $88.6 million Bitcoin theft to trick users into installing ScreenConnect remote access software. [...]
> DHS Is Hiring Bounty Hunters to Find and Photograph Deported People’s Homes Abroad
Homeland Security told immigrants that leaving the US would wipe out fines it claims they owe. Now it wants private investigators to find them in their home countries and collect.
> From 2 weeks to 2 minutes: Amazon Cognito launches Provisioned limits for self-service rate limit management
Imagine preparing for your biggest sales event of the year, and you want to ensure your customer identity management service can handle the elevated traffic for carrying out application activities. For security teams, business leaders, and technologists managing identity infrastructure at scale, thi...
> PSA: Apple’s Private Relay can leak your real IP address
A bug in how Apple implements its Private Relay feature, which in theory masks users’ IP addresses from the sites they visit, can reveal users’ real IP addresses.
> IBM's agentic AI platform is under active attack - patch now
A critical Langflow flaw allowing RCE on default deployments is being exploited, says the CISA
> AEPD - autorité espagnole
L'autorité espagnole de protection des données a constaté une infraction à l'encontre de la Direction Générale de la Garde Civile pour son manquement à l'obligation de réaliser une analyse d'impact relative à la protection des données pour un projet d'assistant virtuel, et ce, même si le projet a ét...
> CNIL
La Commission nationale de l’informatique et des libertés (CNIL) a procédé au renouvellement partiel de son Collège avec la nomination de cinq nouveaux membres à compter du 2 août 2026.Les nouveaux commissaires sont Marie-Luce Cavrois, conseillère honoraire à la Cour de cassation, Marion Fourtune, v...
> ​​Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP)
Learn why KuppingerCole named Microsoft a Leader in its Leadership Compass: Cloud Native Application Protection Platforms report. The post ​​Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP) appeared first on Microsoft Security...
> ICO - autorité britannique
L'autorité britannique de protection des données (ICO) a émis un avis de mise en conformité et un blâme à l'encontre du Service de police métropolitain (MPS) suite à deux divulgations illicites d'informations personnelles.L'autorité a constaté que le MPS n'avait pas mis en place les mesures techniqu...
> CNIL
La Commission Nationale de l'Informatique et des Libertés (CNIL) précise les modalités d'application du droit à l'effacement des données personnelles contenues dans un article de presse en ligne, en équilibre avec la liberté d'expression.Une personne peut demander la suppression de ses données perso...
> Brown Health Medical Group-MA Data Breach Exposes Information of 311,000 Individuals
Brown Health Medical Group-MA breach exposed personal, medical, and financial data of over 311,000 individuals after hackers accessed its servers. Brown Health Medical Group-MA data breach exposed personal, medical, and financial data of over 311,000 individuals after hackers accessed its servers. T...
> Meta Ran Ads That Contained AI-Generated Child Sexual Abuse Imagery
More than 50 offending image and video ads were published across Facebook, Instagram, Messenger, or Threads, according to Meta’s ad library data. Some ran as recently as this week.
> CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws
The U.S. Cybersecurity and Infrastructure Security Agency is giving federal agencies three days to mitigate vulnerabilities in IBM Langflow, N-central, and Apache Tomcat, all actively exploited. [...]