[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (4 articles)

|

// AI-powered summary generated at 12:00

> Vulnérabilité dans Mozilla Firefox pour Android (05 août 2026)
Une vulnérabilité a été découverte dans Mozilla Firefox pour Android. Elle permet à un attaquant de provoquer une atteinte à la confidentialité des données.
> Jochu Technology Co., Ltd.
Le 5 août 2026, la société Jochu et ses filiales (Suzhou Jochu, Xiamen JOCHU et VIETNAM JOCHU) ont détecté un accès non autorisé par des pirates, entraînant une interruption temporaire de leurs systèmes. L'entreprise a immédiatement activé ses protocoles de réponse et fait appel à des experts extern...
> ChainDrop supply chain compromise: Anatomy of a self-propagating worm
A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems by republishing malicious updates. This analysis details the attack chain, affected environments, and practical guidance for detection, hunting, and remediation. The post Chain...
> OpenAI, Anthropic AI agents targeted real people and systems in cyber tests
OpenAI and Anthropic have confirmed that their AI models were involved in separate, newly disclosed third-party cybersecurity testing incidents that resulted in a real website being breached and social engineering attacks against people outside the intended testing boundaries. [...]
> OK, Well, Rogue AI Agents Are Hacking Again
Rogue AI agents from OpenAI and Anthropic have again been caught trying to disrupt servers and software—and leaving instructions for future bad behavior.
> AISI, OpenAI report more ‘unsanctioned’ model hacks
Following similar reports by OpenAI and Anthropic, the UK’s top AI testing lab and a private cybersecurity tester say their models exploited parts of the open internet. The post AISI, OpenAI report more ‘unsanctioned’ model hacks appeared first on CyberScoop.
> ChainDrop credential stealing worm infects over 400 npm packages
A self-propagating worm-like attack is hitting the npm registry, having infected 444 packages from more than a dozen publishers so far. The impact is massive, with the packages affected amounting to more than 2 billion monthly downloads combined. The attack began with the c...
> Appeals Court Agrees with EFF that Building a Web Browser Doesn’t Violate the CFAA
The Ninth Circuit Court of Appeals has endorsed a commonsense technical interpretation of the Computer Fraud and Abuse Act (CFAA), a law not usually given to such interpretation. Amazon had sued Perplexity AI to try to shut down its Comet browser, claiming the browser’s optional agentic AI “Assistan...
> TP-Link patches Omada ZTP flaws allowing hackers to breach networks
TP-Link has patched 15 vulnerabilities in the zero-touch provisioning (ZTP) mechanism of its Omada network devices that could be chained with previously disclosed flaws to achieve remote code execution (RCE). [...]
> Massive supply-chain attack compromises 440 packages under four hours
Researchers from multiple security firms observed a variant of Mini Shai-Hulud, self-replicating malware linked to TeamPCP, in all the affected packages. The post Massive supply-chain attack compromises 440 packages under four hours appeared first on CyberScoop.
> Phishing service spoofs RingCentral to steal Microsoft 365 accounts
The Greatness phishing-as-a-service (PhaaS) platform has expanded from credential phishing to adversary-in-the-middle attacks and device-code phishing targeting Microsoft 365 accounts. [...]
> Apple battles it out again with the UK over encrypted iCloud access
Apple is fighting another attempt by the UK's Home Office to get a backdoor providing access to encrypted iCloud data.
> Android app developers may be unwittingly sharing their users’ location data with advertisers
New findings by the Electronic Frontier Foundation aim to warn app developers that some of the third-party code they place in their apps may also collect their users' location data when they grant permission to the app. 
> OpenAI: Cambodian scam centers used ChatGPT to lure Indian nationals, conduct investment fraud
A tip from WhatsApp led OpenAI to ban multiple accounts associated with investment scams and human trafficking operations based in Cambodian scam centers.
> SharePoint Flaws Used to Hack Switzerland’s Federal IT Agency
Swiss Federal IT Agency FOITT says attackers exploited SharePoint flaws to compromise about 200 accounts. Servers are being rebuilt as investigations continue. Switzerland’s Federal Office for Information Technology and Communications, known as BIT or FOITT, disclosed that unknown attackers had comp...
> GPDP - autorité italienne
L'autorité italienne de protection des données (Garante) sanctionne un établissement de santé pour des manquements liés à la sécurité et à la protection des données dès la conception, ayant permis des accès illicites à des dossiers médicaux. L'autorité a rejeté l'argument selon lequel la responsabil...
> Developers: Beware of Ad Libraries that Betray Your Users’ Location Privacy
Across mobile platforms, advertising companies provide developers with software development kits (SDKs) that make it easy to monetize their apps. But those same SDKs can automatically feed users’ location data into ad systems that location data brokers use to track people. Many developers may not ev...
> Mobile Ad Software Encourages Location Data Sharing, EFF Report Finds
Developers Must Beware of Ad Libraries that Betray Users’ PrivacySAN FRANCISCO – Some software development kits (SDKs) provided by advertising companies to help developers monetize their apps are automatically feeding users’ location data into systems that location data brokers use to track people,...
> Nvidia doesn’t mess around: A week after open AI industry group formed, it’s already showing progress
The week-old Open Secure AI Alliance, spearheaded by Nvidia and grown to over 120 companies, already has proposals out for defending against AI agents.
> New XCSSET variant targets macOS devs via compromised Xcode projects
A new version of the XCSSET malware is targeting thousands of macOS users through compromised Xcode projects and GitHub repositories. [...]