[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (4 articles)

|

// AI-powered summary generated at 12:00

> Nvidia doesn’t mess around: A week after open AI industry group formed, it’s already showing progress
The week-old Open Secure AI Alliance, spearheaded by Nvidia and grown to over 120 companies, already has proposals out for defending against AI agents.
> New XCSSET variant targets macOS devs via compromised Xcode projects
A new version of the XCSSET malware is targeting thousands of macOS users through compromised Xcode projects and GitHub repositories. [...]
> Iran Cyberattacks Against Minnesota Water Systems
Attribution is preliminary, and so far it seems no real damage. And it seems like this is a campaign that has targeted at least seven states. And, because this is where the US is right now, Trump doesn’t believe it’s Iran and that Minnesota…I guess…hacked itself. “I think I blame it on Minnesota bec...
> 77 Open VSX extensions found harvesting developer info
77 extensions on the Open VSX marketplace impersonated legitimate developer tools while transmitting information about the systems and development environments where they were installed. [...]
> Advance Zero Trust for AI: New tools and guidance to secure AI agents and DevSecOps
Microsoft expands its Zero Trust for AI strategy to enhance security for AI and DevSecOps environments with new tools and guidance. The post Advance Zero Trust for AI: New tools and guidance to secure AI agents and DevSecOps appeared first on Microsoft Security Blog.
> 128 Seconds to disruption: Microsoft Defender stops ransomware at QNET 
Microsoft Defender automatically isolated a compromised QNET endpoint in 128 seconds, stopping a multi-stage attack before the payload could persist or spread. The post 128 Seconds to disruption: Microsoft Defender stops ransomware at QNET  appeared first on Microsoft Security Blog.
> Dem senators criticize Trump administration decisionmaking on AI security risks
The five senators said the administration has alternated between being too passive and overstepping, and China stands to benefit as a result. The post Dem senators criticize Trump administration decisionmaking on AI security risks appeared first on CyberScoop.
> Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code phishing, a rapidly growing cyber threat that abuses the legitimate OAuth 2.0 Device Authorization Grant to bypass Multi-Factor Authentication (MFA) and sei...
> Spring 2026 PCI DSS and PCI 3DS compliance packages for AWS now available
Amazon Web Services (AWS) is pleased to announce the successful completion of our Payment Card Industry (PCI) Data Security Standard (DSS) and Three Domain Secure (3DS) certifications. As part of this renewal, we have expanded the scope to include three additional AWS services and one additional AWS...
> Bypassing AI guardrails is so easy a script kiddie can do it
Claiming 'it's my server' was often enough to persuade models to help
> Oracle Linux 10 Node.js Important Bug Fix Advisory ELSA-2026-35842
Oracle Linux 10 has received updates for Node.js packages addressing multiple CVEs, including enhancements and security fixes, ensuring improved software performance and resilience against vulnerabilities.
> Oracle Firefox Important Vulnerabilities Advisory ELSA-2026-47101
Oracle Linux 10 received an updated Firefox package addressing multiple CVEs, introducing changes including fixes to default preferences and an update to ESR version 140.13.0.
> Airlock Digital Unveils Agentic AI Control & Governance to Extend Preventative Endpoint Security
Airlock Digital, a leader in preventative endpoint security, today announced Agentic AI Control & Governance at Black Hat USA 2026. The new capabilities build on application control by providing command- and session-level visibility into trusted AI agent behavior, centrali...
> Oracle Linux 10 ELSA-2026-48032 Nodejs Nodemon Important Security Update
Oracle Linux released an update for nodejs-nodemon version 3.1.14 addressing CVE-2026-13149, available for x86_64 and aarch64 architectures via the Unbreakable Linux Network.
> Oracle Linux 10 nodejs22 Important Multiple Issues ELSA-2026-48033
Oracle Linux 10 has updated RPM packages for Node.js, addressing multiple CVEs including CVE-2026-13149. Versions released include related devel packages and documentation for x86_64 and aarch64 architectures.
> Black Hat USA 2026 – Summary of Vendor Announcements (Part 2)
Many companies are showcasing their products and services this week at the 2026 edition of the Black Hat conference in Las Vegas. The post Black Hat USA 2026 – Summary of Vendor Announcements (Part 2) appeared first on SecurityWeek.
> Oracle Linux 10 Thunderbird Major Update ELSA-2026-49621
Oracle Linux released updated Thunderbird RPMs for version 10, addressing multiple CVEs; the packages are available for x86_64 and aarch64 architectures.
> This one time, at Hacker Summer Camp …
What to expect as BSides, Black Hat, and DEF CON descend on Las Vegas
> Hackers steal over $130M by exploiting bug in offline hardware wallets
A security vulnerability in the cryptocurrency hardware wallet Coldcard is allowing hackers to drain the crypto from victims’ wallets. The total losses amount to more than $130 million, according to blockchain-monitoring firms.
> AEPD - autorité espagnole
L'autorité espagnole de protection des données a sanctionné un important sous-traitant des secteurs bancaire et immobilier pour des mesures de sécurité insuffisantes ayant conduit à une cyberattaque de grande ampleur, ainsi que pour avoir notifié cette violation avec un retard significatif.Faits et...