> TODAY'S SUMMARY (13 articles)
Today's cybersecurity landscape highlights two critical zero-day vulnerabilities in Citrix NetScaler (CVE-2026-88771 and CVE-2026-88772), which have been actively exploited for remote code execution before patches were available. Cloudflare also addressed a significant flaw in its Containers service that could expose customer data across tenants. Additionally, Microsoft SharePoint vulnerability (CVE-2026-65660) has been added to CISA's KEV catalog, indicating it is being exploited in the wild. In the cybercrime arena, a Kosovo national faces severe penalties for operating a marketplace selling stolen data and fraud tools. As automated traffic surges, the ongoing evolution of AI continues to reshape the cybersecurity landscape, as noted in Cloudflare's annual founders' letter.
|
// AI-powered summary generated at 20:00
Most phishing campaigns rely on the fact that the victim is afraid to loose "something": money, access to information, ... Many brands have been impersonated by campaigns but I spotted some phishing emails that focus on AI services like ChatGPT.
Oracle Linux has released updated RPMs for version 8, addressing CVEs 2026-55653 and 2026-55655, which fix security vulnerabilities in OpenSSH affecting both x86_64 and aarch64 architectures.
Oracle Linux 9 has released updated RPMs addressing multiple CVEs, including kernel improvements, module signing updates, and various bug fixes to enhance system security and functionality.
Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution.
The vulnerability, tracked as CVE-2026-48449, carries a severity score of 10.0 on the CVSS...
Oracle Linux 10 has updated nodejs24 packages to version 24.18.0, addressing multiple CVEs and improving security, with rpms available for x86_64 and aarch64 architectures.
Oracle Linux has released updated Java 25 RPM packages for version 10, addressing several CVEs and including various updates and changes to dependencies and documentation.
A fake browser update served over hijacked hotel Wi-Fi has been used to deliver CornFlake, a remote access trojan (RAT) that can capture webcam images, microphone audio, and keystrokes, Microsoft said in its latest report.
Researchers track the operation as CaptiveCrunch and attribute it to Storm-2...
Oracle Linux updated its kernel packages for version 10 to address multiple security vulnerabilities, introducing enhancements such as new driver signing certificates and fixes for identified CVEs.
In July 2026, the Russian VPN service SplitVPN (previously known as NotVPN) suffered a data breach. The incident exposed millions of customer records, including 865k unique email addresses. Other impacted data included IP addresses, the user's country, and partial payment card data (first 6 and last...
Test du DXRacer Martian, le fauteuil gaming haut de gamme : dossier motorisé, support lombaire, assise chauffante et ventilée, et confort au quotidien.
Le post Test du DXRacer Martian, le fauteuil gaming électrique haut de gamme a été publié sur IT-Connect.
Debian has released advisory DSA-6408-1 addressing multiple vulnerabilities in Chromium that could lead to code execution, denial of service, or information disclosure, urging users to upgrade.
La société Daisen a annoncé qu'un accès non autorisé à son système avait été détecté. L'incident, qui a débuté vers 2h du matin le 1er août, a entraîné une infection par un logiciel malveillant. Suite à la détection, l'entreprise a coupé tous ses systèmes internes, ce qui a affecté ses opérations de...
La ville de Norcross (Géorgie) a été victime d'une cyberattaque par ransomware qui a affecté certains de ses systèmes informatiques au début du mois d'août. Les autorités ont fait appel à des experts externes en cybersécurité et ont prévenu les résidents que des perturbations limitées pourraient enc...
Running a website means a single unpatched vulnerability can take it offline, harm your reputation, or require cleanup. Most compromises begin with automated attacks exploiting known software flaws, usually reported and disclosed already.
To keep you protected from these threats, we’ve compiled this...
Le Hotel Ózon a a été victime d'une cyberattaque par rançongiciel, qui a rendu son système informatique inaccessible. Les attaquants ont chiffré les sauvegardes et ont exigé 25 000 euros. L'incident, détecté le 1er août 2026, a affecté les données de réservations allant du 1er novembre 2022 au 31 ju...
Les autorités polonaises enquêtent sur une cyberattaque visant la chaîne de magasins Zabka. L'incident, survenu au début du mois d'août, concernait un accès non autorisé à certains systèmes informatiques utilisés pour l'échange d'informations entre le franchisé et le franchisé. L'attaque, attribuée...
Oracle Linux has released security updates for libXfont2, addressing CVEs 2026-56001 and 2026-56002, available for x86_64 and aarch64 architectures on the Unbreakable Linux Network.
La Ville de Gagny a subi une cyberattaque ayant affecté une partie de son système d’information. Des personnes non autorisées ont pu accéder à certaines données personnelles des administrés, notamment nom, prénom, adresse, coordonnées téléphoniques et électroniques, ainsi que des informations admini...
Levi Strauss a divulgué un incident de cybersécurité récent où un tiers non autorisé a accédé aux systèmes de l'entreprise grâce à une attaque d'ingénierie sociale ciblant trois employés. Bien que l'incident n'ait pas perturbé les opérations commerciales, les premières conclusions indiquent qu'une c...
Oracle Linux 10 released updated Pipewire RPMs addressing CVE-2026-5674, featuring version 1.4.11 for x86_64 and aarch64 architectures, improving audio functionalities and security.