[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> Hims & Hers sued over alleged health data privacy failures
The FTC has sued telehealth provider Hims & Hers, alleging it shared customers' sensitive health information with advertisers.
> USN-8625-1: OpenSSL vulnerability
It was discovered that OpenSSL incorrectly allocated memory buffers in the SSL/TLS state machine when receiving handshake data. A remote attacker could possibly use this issue to cause OpenSSL to consume excessive memory, leading to a denial of service. This issue is known as the "HollowByte" denial...
> Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database
A now-patched vulnerability in Azure Cosmos DB could have let an attacker escape the service's Gremlin query sandbox and obtain full read and write access to databases across customer tenants, according to Wiz. Wiz, which codenamed the chain CosmosEscape, said the exploit chain began with a crafted...
> FTC sues Hims & Hers for allegedly sharing patients’ medical data with advertisers Meta and Snap
The U.S. federal consumer watchdog said Hims & Hers, which prescribes for sexual wellness and mental health conditions, used website trackers to share customers' information with advertisers.
> AI agents gain access to financial workflows amid growing governance gaps
AI agents are now being allowed to create business records, approve transactions, and execute financial workflows. ERP security firm Pathlock says most organizations don’t know if that is all they are doing. The company’s 2026 AI Governance Gap Report found that 79% of orga...
> AI and Automation Fall Short of Sysadmin Expectations
Action1 report finds sysadmins overestimated their use of AI in predictions made two years ago
> North Korean hackers behind major open-source supply chain attacks, Amazon says
A North Korea-linked hacker group was behind several high-profile compromises of open-source software libraries used by developers worldwide, researchers have found.
> Dogfooding at scale: migrating cdnjs to Cloudflare’s Developer Platform
We moved cdnjs, serving 9 billion requests a day, entirely onto Cloudflare's Developer Platform. That means we’re running one of the Internet's busiest open-source CDNs on our own building blocks, and we pushed Workflows and Workers limits higher for everyone.
> Discern Security Raises $13 Million in Series A Funding
The company will invest in accelerating the development and adoption of its agentic platform. The post Discern Security Raises $13 Million in Series A Funding appeared first on SecurityWeek.
> Cantina Emerges From Stealth With $8 Million in Funding
The startup’s community-powered agentic security platform helps proactively identify, prioritize, and remediate vulnerabilities. The post Cantina Emerges From Stealth With $8 Million in Funding appeared first on SecurityWeek.
> Hidden prompt turns Microsoft Copilot into an AI worm
A new type of attack can trick Microsoft Copilot for Word into spreading hidden prompt injections from document to document.
> Analog Devices Discloses Data Breach After Unauthorized System Access
Chipmaker Analog Devices disclosed a data breach after detecting unauthorized access to systems on June 23. The investigation is ongoing. Semiconductor giant Analog Devices (ADI) disclosed a data breach following a cyberattack that resulted in unauthorized access to some of its systems on June 23. A...
> Critical Ruflo flaw lets attackers hijack AI agents through exposed MCP bridge
A critical vulnerability in the open-source AI agent platform Ruflo could allow unauthenticated attackers to take control of enterprise AI environments by exploiting an exposed Model Context Protocol (MCP) bridge, according to research published by Noma Security. The flaw,...
> Onyx Security Raises $113 Million to Control AI Agents in the Enterprise
The Series B funding round brings the total raised by Onyx Security to $153 million.  The post Onyx Security Raises $113 Million to Control AI Agents in the Enterprise appeared first on SecurityWeek.
> CISA sets a new SBOM baseline
The US Cybersecurity and Infrastructure Security Agency (CISA), together with its co-authoring partners, has released the 2026 Minimum Elements for a Software Bill of Materials (SBOM), replacing the 2021 guidance published by the National Telecommunications and Information Administration (NTIA). An...
> ‘DangleGeddon’: AI Could Weaponize Forgotten DNS Records at Global Scale
Researchers warn that AI could turn dangling DNS takeovers into a nation-state weapon capable of disrupting governments, banks and global supply chains. The post ‘DangleGeddon’: AI Could Weaponize Forgotten DNS Records at Global Scale appeared first on SecurityWeek.
> The First 60 Minutes of Digital Evidence: The Investigator Advantage
The first 60 minutes on scene often decide the rest of the case – Richard Frawley of ADF Solutions breaks down how to identify, preserve, and triage digital evidence before you leave the property.
> Teams-Themed Phishing Campaign Abused Legitimate Microsoft Login Pages
Check Point researchers detail phishing attack as an example of attackers dropping fake Microsoft login pages in favor of abusing Microsoft’s legitimate authentication infrastructure
> Cyber extortionists steal data from UK Department for Education
Cybercriminals are attempting to extort Britain’s Department for Education (DfE) after compromising what the hackers said was more than 600,000 pieces of data allegedly including names, email addresses and phone numbers.
> Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents
Hidden instructions in a Word document can make Microsoft 365 Copilot rewrite figures in a report, then copy the same instructions into the finished file. Håkon Måløy disclosed the technique on July 28, 144 days after reporting it to Microsoft. In his proof of concept, the internally generated file...