[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (10 articles)

|

// AI-powered summary generated at 16:00

> Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers
The biggest single reward paid out by Microsoft between July 1, 2025, and June 30, 2026, was $200,000. The post Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers appeared first on SecurityWeek.
> Secure Agent Harness Execution: Preventing Escape
> Analysts got 19 minutes back every hour in Stellar Cyber’s agentic auto triage trials
An analyst opening a queue on Monday morning will spend most of it on tickets that amount to nothing. Stellar Cyber’s Agentic Auto Triage closed 8,047 of those tickets on its own during customer trials, filing them as confident false positives. That covers 64% of every verdict the software issued. A...
> Cloudflare has mostly ditched third party security tools, suggests not trying that at home
Automates bug bounty triage with Sonnet for $58 a month, CSO says Mythos would cost $200k
> Fake IRS letters direct crypto holders to bogus compliance portal
Scammers are sending physical letters to cryptocurrency holders that copy the look of official IRS notices. The letters tell recipients they must enroll in something called a Digital Asset Compliance Portal before a deadline, or risk penalties. “If you receive a letter claiming to be from the IRS th...
> Gufw : gérer le pare-feu UFW sous Linux avec une interface graphique
Découvrez Gufw, l'interface graphique UFW sous Linux : installation, création des règles de pare-feu et bonnes pratiques, sans passer par la ligne de commande. Le post Gufw : gérer le pare-feu UFW sous Linux avec une interface graphique a été publié sur IT-Connect.
> Cybersecurity jobs available right now: August 4, 2026
Application Security Engineer Arcadia | USA | Remote – View job details As an Application Security Engineer, you will lead the application vulnerability management process by prioritizing and driving remediation of security findings. You will integrate and automate security tools within CI/CD pipeli...
> ISC Stormcast For Tuesday, August 4th, 2026 https://isc.sans.edu/podcastdetail/10036, (Tue, Aug 4th)
> New York Awards $9 Million to Strengthen Cybersecurity at 153 Water Systems
The grants will help local governments assess and improve cyber defenses amid a multistate campaign targeting water and wastewater infrastructure. The post New York Awards $9 Million to Strengthen Cybersecurity at 153 Water Systems appeared first on SecurityWeek.
> Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts
Microsoft has linked a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard, also known as APT29. [...]
> Foresee Pharmaceuticals
Foresee a immédiatement activé ses mécanismes de défense en matière de sécurité de l'information et a fait appel à des entreprises et à des experts externes spécialisés dans la cybersécurité afin de contenir la faille, d'en évaluer l'ampleur et de renforcer l'infrastructure réseau. D'après l'évaluat...
> North Carolina Ports
Les Ports de Caroline du Nord ont été victimes d'une cyberattaque qui a perturbé les opérations de leurs trois installations portuaires. L'incident, survenu le mardi soir, a nécessité l'activation du plan de contingence en cybersécurité et le passage à un traitement manuel des portes. L'attaque est...
> N-able N-central exploitation results in RMM tool deployment
After compromising systems via CVE-2026-18577, threat actors use the additional RMM tools and network tunnels to establish persistent remote access
> The AME Group
La Vincennes Community School Corporation a dû fermer temporairement ses serveurs et les services de téléphone et internet de tous les bâtiments scolaires suite à une attaque par ransomware affectant son fournisseur technologique, AME, qui était lui-même victime d'une attaque impliquant l'un de ses...
> Interlock ransomware gang creates volatile situation
Multiple legitimate DFIR tools abused by GOLD EMBRACE double-extortion specialists
> Worm compromises hundreds of popular npm packages
On August 4, 2026, several popular npm packages, including 'keyv', were compromised to deliver malware.
> Multiples vulnérabilités dans Google Android (04 août 2026)
De multiples vulnérabilités ont été découvertes dans Google Android. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.
> Multiples vulnérabilités dans Traefik (04 août 2026)
De multiples vulnérabilités ont été découvertes dans Traefik. Elles permettent à un attaquant de provoquer un contournement de la politique de sécurité.
> New Pass-ta-key attacks let malware hijack Google-synced passkeys
Security researchers have discovered three attacks that allow malware on already-compromised Windows devices to abuse Google Password Manager's synced passkeys to take over accounts, bypass user verification, and extract passkey private keys. [...]
> Multiples vulnérabilités dans les produits Tenable (04 août 2026)
De multiples vulnérabilités ont été découvertes dans les produits Tenable. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une atteinte à l'intégrité des données et une injection SQL (SQLi).