[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (10 articles)

|

// AI-powered summary generated at 16:00

> Fake Roblox Xeno script launcher pushes infostealer, RAT malware
Fake Xeno Executor installers are infecting unsuspecting Roblox players with malware that provides remote access and steals sensitive information. [...]
> Apple challenges UK government’s latest demand for iCloud backdoor: report
Apple has appealed a new legal demand by the U.K. government, which critics say could threaten the privacy rights of users all over the world.
> 18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users
Cybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a cross-platform remote access trojan (RAT) as part of a sophisticated, targeted software supply chain attack targeting Chinese-speaking environments. One of the packages...
> Hackers steal 31,000 records identifying people behind Liechtenstein companies, foundations
A cyberattack compromised tens of thousands of records related to companies, foundations and trusts in Liechtenstein, prompting the government to to form a “crisis unit” to address the breach.
> Knowledge Base Digest - July 2027
Articles How devices become active in NDR Does AuthPoint support the WS* protocols Endpoint Security identifies legitimate ScreenConnect installations as malware WatchGuard access points reported as Evil Twin and suspected Rogue APs Who pays for shipping for my RMA? If I do not send back the defect...
> AI slop pollutes the CVE pipeline with fake vulns
With NIST still buried under its backlog, expect AI-generated bogus reports to continue
> More on the OpenAI Agent’s Attack on Hugging Face
Hugging Face has published a detailed timeline of the attack. From the summary: The agent was running an internal OpenAI cyber-capability evaluation based on the ExploitGym benchmark, which tasks an AI agent with finding and exploiting software vulnerabilities. OpenAI ran this on its own infrastruct...
> N-able warns of N-central auth bypass flaw exploited in attacks
N-able is warning customers that hackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) affecting both hosted and on-premises N-central servers. [...]
> GPDP - autorité italienne
Un défaut de robustesse dans le code d'une application, ayant entraîné une communication non autorisée de données, est sanctionné au titre des articles 25 et 32 du RGPD, même si l'incident était de courte durée et sans conséquences permanentes pour les personnes concernées.Faits et contexteL'autorit...
> AEPD - autorité espagnole
Une signalisation de vidéoprotection obsolète et incomplète, même si elle est corrigée en cours de procédure, constitue un manquement à l'obligation de transparence de l'article 13 du RGPD.Faits et contexteL'Agence Espagnole de Protection des Données (AEPD) a aujourd'hui publié une décision de sanct...
> Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts
Malware running as an ordinary user on a Windows machine can sign into a victim's passkey-protected accounts without a fingerprint, a PIN, or anything at all appearing on the victim's screen. Unit 42 detailed three attack paths against Chrome's Google Password Manager cloud authenticator, which it...
> AEPD - autorité espagnole
L'autorité espagnole de protection des données (AEPD) a clôturé une procédure concernant l'installation d'une caméra de surveillance dans un véhicule, estimant que la simple présence du dispositif, sans preuve de son activation et donc d'un traitement de données, ne suffit pas à caractériser une inf...
> AEPD - autorité espagnole
L'autorité espagnole a constaté un manquement au principe d'intégrité et de confidentialité (article 5.1.f) du RGPD à l'encontre d'une administration publique, suite à une violation de données résultant de l'exploitation de vulnérabilités connues et de l'absence de mesures de sécurité de base, telle...
> INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws
The INC Ransomware operation has emerged as the "dominant threat actor" exploiting the recently disclosed security flaws in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. In a report published over the weekend, Resecurity said it observed the INC Ransomware accelerating its activi...
> GPDP - autorité italienne
L'autorité de contrôle italienne (Garante) a sanctionné une société pour avoir envoyé des communications commerciales sans base légale valide, en considérant à tort qu'un contrat était formé dès la soumission d'un formulaire en ligne, sans attendre la confirmation de l'adresse électronique par l'uti...
> LLM Heist: Hijacking LiteLLM for Traffic Interception, Key Theft, and Tool-Call Injection
LiteLLM is a popular AI gateway. It provides a unified interface to LLMs and simplifies governance. It also has access to the backend LLM provider keys. All of that makes it a high-value target. Not only for IP and data theft, but also for response modification and tool invocation. This post walks...
> [Webinar] Tales from the Frontlines: An exclusive briefing on Q2 incidents
Register for an exclusive, unrecorded 30-minute webinar to review the most high-impact incidents Talos IR faced in Q2.
> Qu’est-ce qu’un WAF ? Principes et mise en pratique
C'est quoi un WAF (Web Application Firewall) ? Découvrez son rôle face aux cyberattaques, les solutions open source et déployez le vôtre avec ModSecurity. Le post Qu’est-ce qu’un WAF ? Principes et mise en pratique a été publié sur IT-Connect.
> AI Runs the Hack: Chinese Actor Automates Cyberattacks With DeepSeek
Unit 42 uncovered an AI-driven Chinese hacking campaign where DeepSeek autonomously scanned targets, selected exploits, and launched attacks. Researchers at Palo Alto’s Unit 42 got a front-row seat to something they’d only theorized about before: an AI system running an actual hacking campaign with...
> Black Hat USA 2026 – Summary of Vendor Announcements (Part 1)
Many companies are showcasing their products and services this week at the 2026 edition of the Black Hat conference in Las Vegas. The post Black Hat USA 2026 – Summary of Vendor Announcements (Part 1) appeared first on SecurityWeek.