[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (1 articles)

|

// AI-powered summary generated at 04:00

> AP - autorité néerlandaise
L'Autorité de protection des données néerlandaise (AP) a publié des lignes directrices à destination des organismes de garde d'enfants concernant le partage d'informations en cas de soupçons d'infractions pénales, notamment d'abus sur mineurs.Ces clarifications portent sur le processus de recrutemen...
> AEPD - autorité espagnole
L'autorité espagnole a constaté une violation de l'obligation de coopération à l'encontre d'un organisme public, même si la procédure initiale ayant conduit aux demandes d'information a été déclarée caduque.Faits et contexteL'autorité espagnole de protection des données (AEPD) a aujourd'hui publié u...
> Word worm crawls into Copilot, spreads chaos
Researcher says months of coordination with Microsoft have yet to produce a robust mitigation
> BfDI - autorité allemande
Le Préposé fédéral à la protection des données et à la liberté d'information (BfDI) a pris position sur un projet de réforme de la Loi sur la liberté d'information (IFG) qui pourrait aboutir à sa suppression de fait au niveau national.Suite à son 8ème symposium sur la liberté d'information, le BfDI...
> Huntress warns about attack spree that hit 30 SonicWall customers in 2 days
Unknown attackers broke into 92 unique SonicWall user accounts with legitimate credentials, researchers said. The post Huntress warns about attack spree that hit 30 SonicWall customers in 2 days appeared first on CyberScoop.
> OpenAI agent used exposed credentials at 4 services in Hugging Face breach
In a new update, OpenAI says its AI models also used publicly exposed credentials to compromise accounts on four third-party services during the recent attack on Hugging Face, expanding the scope of the four-day security incident to other organizations. [...]
> WP2Shell WordPress Exploit Technical Analysis and Real Attack Data
On July 17th, 2026, the WordPress Security Team released updates to WordPress core addressing a critical vulnerability chain that can be leveraged by unauthenticated attackers to create an administrator account and then execute code through normal administrator capabilities, such as uploading a plug...
> ​​Better security starts with better questions
Learn how better questions, trusted AI, and human judgment help security leaders make confident decisions and build resilient systems. The post ​​Better security starts with better questions appeared first on Microsoft Security Blog.
> LogoKit Phishing Kit Screenshots Victim Sites in Real Time
LogoKit now builds per-victim phishing pages using live screenshots of the target's real website
> ScreenConnect leveraged in cyberattacks | Kaspersky official blog
We analyze a campaign that leverages ScreenConnect: distribution through fake websites, AsyncRAT deployment, evasion tactics, and organizational defense recommendations.
> Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory
Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that could result in unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726 (CVSS score: 10.0), impacts all ve...
> Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape
Broadcom has released security updates to address multiple security flaws impacting VMware ESX, vCenter, Workstation, and Fusion, three of which have been designated as critical in severity. The first of the three critical-rated flaws is CVE-2026-59309 (CVSS score: 9.8), which has been described as...
> Mythos takes its first shot at post-quantum cryptography
Anthropic’s Claude Mythos Preview model has helped researchers discover ways to speed up attacks against two widely studied cryptographic algorithms. One of the targets is Hawk, a candidate for post-quantum digital signature algorithms currently being evaluated by NIST, whi...
> AI robocalls: Why caller ID is still lying to you
AI is making robocall scams cheaper, more convincing, and harder to spot. Here's why caller ID still isn't enough.
> Sweet Security Brings Autonomous Protection to the AI Enterprise with New Blocking Capabilities
Sweet Security, the proactive runtime enforcement company for cloud and AI, today announced its further expansion into AI security with Agentic AI Blocking. Sweet now blocks rogue agent behavior in real time – extending Sweet’s runtime enforcement from the cloud to the AI agen...
> Russian-Alligned TA488 Returns With Persistent Outlook Web Access Attack
TA488 returned with OWA half-click exploit deploying OWAReaper implant that survived re-imaging
> Deepfakes Are Now An Investigative Risk – Unmasked: Authenticity Must Be Assessed
Deepfakes can waste critical investigative time, but S21 Deepfake Detector helps teams assess images and video frames for synthetic or manipulated content quickly, securely, and entirely offline.
> Hackers target over 30 Minnesota water utilities in coordinated OT attack
The Minnesota IT Services (MNIT) agency activated its cybersecurity incident response capabilities across the entire state after hackers targeted more than 30 community water systems in "a coordinated cyberattack." [...]
> Secure your npm and pip package updates in Amazon Linux
If you use and install packages from npm or PyPI, the first hours after a package is published are the riskiest because scanners can’t analyze packages before publication. Recent supply chain events affecting NodeJS and Python packages have been detected and removed within hours. However, while thos...
> Laundry Bear’s webmail hackers had more in store after February, report says
Researchers say the Russian state-linked hacking group tracked as Laundry Bear recently began exploiting a bug in Microsoft Outlook Web Access.