[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (13 articles)

|

// AI-powered summary generated at 20:00

> Welcome to Agents Week
Agents Week explores how cloud infrastructure must evolve to serve autonomous agents rather than human browsers. Join us as we unpack the storage, execution, and security primitives needed for an agent-native web.
> Google Chrome may soon block New Tab hijacker extensions by default
Google is preparing a new Chrome security feature that would block policy-installed extensions from hijacking the New Tab page or changing the default search engine. [...]
> Week in review: Claude breached three companies during tests, AD CS domain-takeover PoC released
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Nono: Open-source sandbox for AI agents AI coding agents run with the same permissions as their users, meaning they can access sensitive files, credentials, and production systems. A prompt injection, h...
> Debian libssh Important Denial of Service Arbit Code Exec DSA-6410-1
Debian announced the fix of multiple vulnerabilities in libssh that could lead to denial of service, information disclosure, and arbitrary code execution, urging users to upgrade their packages.
> CISA Urges Utilities to Remove Internet-Exposed PLCs After Minnesota Attacks
After attacks hit 30+ Minnesota water systems, CISA urged utilities to remove internet-exposed PLCs and strengthen OT security. Between Sunday and Monday, July 26 and 27, a coordinated cyberattack hit operational technology (OT) systems at more than 30 community water utilities across the state, acc...
> Atomic MacOS (AMOS) stealer infection, (Sun, Aug 2nd)
Introduction
> Chambre des salariés (CSL)
La Chambre des salariés (CSL) a confirmé avoir été victime d'une attaque informatique impliquant un accÚs non autorisé à certains de ses serveurs. L'incident est actuellement contenu, mais des investigations approfondies sont en cours pour déterminer l'origine, la période, l'étendue et les conséquen...
> Techventures Bank S.A.
Le DNSC (Directoratul Național de Securitate Cibernetică) a fourni son assistance Ă  Techventures Bank S.A. aprĂšs qu'elle ait signalĂ© une cyberattaque par ransomware. L'incident a Ă©tĂ© notifiĂ© le 2 aoĂ»t 2026. Les autoritĂ©s collaborent avec la banque pour limiter les effets de l'attaque et enquĂȘter sur...
> Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes
An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integr...
> Magyar Államkincstår
Le Magyar ÁllamkincstĂĄr (TrĂ©sor d'État hongrois) a Ă©tĂ© victime d'une cyberattaque ciblant le rĂ©seau informatique de son service agricole et de dĂ©veloppement rural (Nemzeti KifizetƑ ÜgynöksĂ©g). L'incident a Ă©tĂ© dĂ©tectĂ© et les serveurs infectĂ©s ont Ă©tĂ© isolĂ©s. Les autoritĂ©s compĂ©tentes, dont le Centre...
> Rails patches critical Active Storage flaw with RCE potential
A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]
> Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens
Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group al...
> Cyber’Smile : la playlist d’étĂ© de ZATAZ est de sortie
Entre deux alertes cyber et un Wi-Fi d’hĂŽtel douteux, ZATAZ passe en mode Ă©tĂ© avec une playlist de cinq titres originaux pour accompagner vacances, trajets et pauses au soleil.
> Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic
Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation...
> Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments
The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.
> Ruby on Rails Patches Critical Vulnerability
The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.
> 7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran
Plus: The FBI eyes AI-powered tech to detect future crimes, Russia charges Telegram’s founder, xAI sues to stop a state’s “nudification” ban, and the Democrats learn a lesson about getting scammed.
> Nobody Knows if OpenAI’s and Anthropic’s AI Hacking Sprees Are Illegal
Both major AI labs’ models broke containment, escaped onto the internet, and hacked other companies. If a human had done that, the law would likely be against them. But a bot?
> Debian libgd2 Important Denial of Service CVE-2026-9672
Debian issued a security advisory for libgd2, addressing a vulnerability that could lead to denial of service or arbitrary code execution, urging users to upgrade their packages.
> Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites
Attackers modified a JavaScript file served by advertising technology company Adform, turning it into a browser-side tool that rewrites cryptocurrency wallet addresses. Adform detected the incident on July 27, 2026, removed the malicious code, notified affected clients, and reported it to authoriti...