[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (1 articles)

|

// AI-powered summary generated at 04:00

> Apple accused of letting fake crypto app steal $1.8 million
The case raises fresh questions about how effectively Apple polices apps that impersonate legitimate developers.
> Cisco warns of FMC static credential flaw exploited in zero-day attacks
Cisco is warning that a high-severity Secure Firewall Management Center (FMC) static credential vulnerability, tracked as CVE-2026-20316, was actively exploited in zero-day attacks to gain unauthorized access to vulnerable devices. [...]
> Claude Mythos Shows AI Can Outpace Human Cryptography Research
Claude Mythos found new flaws in HAWK and reduced AES, proving AI can autonomously advance cryptography research. Anthropic published two cryptographic research results achieved by Claude Mythos Preview working mostly autonomously: an improved attack on HAWK, a post-quantum digital signature scheme...
> A little-known npm package was North Korea’s warm-up act for the axios hack
Amazon's threat intelligence team traced domain records from the open-source software hack to a smaller, earlier compromise by the same North Korean group. The post A little-known npm package was North Korea’s warm-up act for the axios hack appeared first on CyberScoop.
> Amazon identifies North Korean hacker group behind open-source supply chain attacks
Amazon is sharing new findings about how a threat actor linked to the Democratic People’s Republic of Korea (DPRK) is targeting open source software libraries, the shared building blocks that companies around the world use to develop applications. Amazon Threat Intelligence has linked several recent...
> Anthropic confirms Claude is down worldwide
[...]
> Supply chain challenges loom large in quantum race, White House official says
Brad Blakestad, director of the National Quantum Coordination Office, also said encryption and measuring progress would pose challenges. The post Supply chain challenges loom large in quantum race, White House official says appeared first on CyberScoop.
> Debian DSA-6403-1 nss Important Arbitrary Code Execution Fix
Debian announced a security fix for nss library due to a flaw that could allow arbitrary code execution via crafted certificates, urging users to upgrade packages.
> Hackers Strike Minnesota Water Utilities, One Plant Briefly Offline
Coordinated OT cyberattacks hit 30+ Minnesota water utilities, briefly disrupting one plant. Backup procedures prevented major water service impacts. Minnesota just had its own live-fire lesson in what happens when someone targets water utilities at scale. Between Sunday and Monday, July 26 and 27,...
> USN-8624-1: Sinatra vulnerability
It was discovered that Sinatra did not properly handle header parsing, causing ETag generation to hang when given specific input. A remote attacker could possibly use this issue to cause a denial of service.
> Closed models refuse to help researcher swat Linux bug
"I'm sorry, Dave. I'm afraid I can't do that" is an effective sales pitch for open source
> Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads
Ruby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files from application servers through crafted image uploads. Tracked as CVE-2026-66066 (CVSS score: 9.5), the flaw can expose the Rails process environment and secre...
> Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare
Health-ISAC is warning healthcare and medical technology organizations of an observed increase in successful attacks by ShinyHunters, which are using social engineering to compromise single sign-on accounts and steal data from cloud services. [...]
> US government bans new foreign-made humanoids, robot dogs, and solar inverters, citing risks to national security
The ban largely affects U.S. imports from China, which currently dominates the global market for making humanoid robots and solar inverters.
> OpenAI says rogue agent behind Hugging Face hack broke into additional services
The four additional targeted organizations weren’t named. OpenAI said they were not affected as severely as Hugging Face.
> Measuring the Tendency of AI Agents to Go Rogue
This essay was written with Barath Raghavan, and originally appeared in The Guardian. In July, Hugging Face, a company that hosts much of the world’s AI software and open-source AI models, was hacked. A malicious dataset had been used to run code on one of its servers. Whoever was behind it captured...
> Monitoring Privacy Blockchains: How Compliance Teams Can Stay a Step Ahead
Summary Institutions are shaping blockchain design: A new generation of hybrid blockchains are building capabilities that suit the privacy-forward needs
 The post Monitoring Privacy Blockchains: How Compliance Teams Can Stay a Step Ahead appeared first on Chainalysis.
> AEPD - autorité espagnole
L'autorité espagnole de protection des données a classé une procédure pour traitement illicite de données, considérant que les faits avaient déjà été jugés et sanctionnés par une juridiction pénale.Faits et contexteL'autorité espagnole de protection des données (AEPD) a publié une décision de classe...
> Buying TikTok views or followers? Here’s what you’re really getting
Behind TikTok's booming growth industry are fake engagements, stolen accounts, and a fast track to getting flagged.
> 🏃 Fitness Tracker Privacy Fails | EFFector 38.14
Watches, bands, and rings—if you want to digitally monitor your fitness, more companies than ever are selling devices to do it. And more Americans than ever now own at least one wearable health device. But what are the companies that make fitness trackers doing to protect our sensitive data from pry...