[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (18 articles)

|

// AI-powered summary generated at 16:01

> ANSPDCP - autorité roumaine
L'Autorité Nationale de Surveillance du Traitement des Données à Caractère Personnel de Roumanie (ANSPDCP) a publié son rapport d'activité pour l'année 2025, synthétisant ses actions de contrôle, de conseil et ses activités internationales.En 2025, l'autorité a traité 12 297 plaintes, signalements e...
> PIPC - autorité sud-coréenne
L'autorité sud-coréenne a conclu son enquête sectorielle sur les pratiques de cinq grands fabricants d'aspirateurs robots, soulignant une gestion globalement sécurisée des données mais identifiant des lacunes en matière de conformité formelle, notamment sur l'information des utilisateurs et les tran...
> New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing
Researchers have disclosed a new hardware attack, called DDRop, that breaks the memory protection in Intel and AMD confidential computing by silently dropping writes to a server's memory, so the processor keeps reading old encrypted data as if it were current. The attack requires an attacker who al...
> AEPD - autorité espagnole
L'autorité espagnole de protection des données a classé une procédure de sanction pour violation de la confidentialité, estimant que la preuve de la divulgation non autorisée de documents par le responsable du traitement n'était pas rapportée. En l'absence de certitude sur l'origine de la fuite, l'a...
> AEPD - autorité espagnole
L'autorité espagnole de protection des données (AEPD) a sanctionné une société hôtelière pour avoir publié le numéro de téléphone personnel d'une ancienne employée comme contact de l'établissement sur une plateforme de réservation, sans disposer d'une base juridique valable.Faits et contexteL'autori...
> Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries
A Chinese threat actor tracked as Red Heron has been attributed to the rapid exploitation of a recently disclosed security vulnerability in Gitea to compromise internet-facing instances as part of a multi-national campaign. "Red Heron scanned 1,386 Gitea instances across seven countries and maintai...
> Wordfence Argus Identifies Two Critical Unauthenticated Vulnerability Chains Leading to Remote Code Execution in The Events Calendar Plugin
On August 21 and August 22, 2026, Wordfence Argus, created by the Wordfence Threat Intelligence team, identified two independent critical vulnerability chains in The Events Calendar, a WordPress plugin active on more than 600,000 websites. Both chains begin in the plugin's widget-rendering pipeline...
> New York Seizes a Dozen Celebrity Deepfake Websites
In the biggest-ever legal action against harmful deepfake websites, the Manhattan District Attorney’s Office has seized 12 sites that collectively targeted around 1,200 victims.
> Pro-Ukraine Hacking Cat group deploying new malware against Russian targets
The pro-Ukraine hacktivist group Hacking Cat has evolved from carrying out website defacements and data leaks to more sophisticated and destructive attacks on Russian targets, researchers said.
> Hackers target exposed Vite dev servers to steal AWS, Azure secrets
A mass-scanning campaign targeting internet-exposed Vite development servers is attempting to steal cloud credentials and configurations from AWS and Azure deployments. [...]
> PaperCut NG/MF : 395 organisations dans 48 pays compromises par des agents IA
Des centaines d'agents IA ont exploité deux failles PaperCut NG/MF et compromis 440 serveurs chez 395 organisations dans 48 pays, dont 31 en France. Le post PaperCut NG/MF : 395 organisations dans 48 pays compromises par des agents IA a été publié sur IT-Connect.
> Using AI for Weapons Development
Last week, Anthropic released a long and detailed document describing current misuses of their Claude models. I’m still reading it, but I wanted to flag this: We identified a cell of threat actors based in northern Yemen running three weapons development programs: a guided rocket that used a commodi...
> Hundreds of fake government websites target users in Central Asia
The sites are designed to collect victims’ contact details, which scammers then use to target them through phone or email to steal money, personal information or gain access to their devices.
> WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution
WordPress has announced it's launching an automated security review for every release of a plugin before it's distributed through the WordPress.org update API so as to analyze it for potential security issues and ensure there are no risks involved. "New plugins are reviewed before they enter the di...
> Portabase : une solution open source pour centraliser la sauvegarde de vos bases de données
Découvrez Portabase, la solution open source de sauvegarde de bases de données. Installation Docker, configuration d'un agent, etc... Prise en main complète. Le post Portabase : une solution open source pour centraliser la sauvegarde de vos bases de données a été publié sur IT-Connect.
> Protecting your smart TV and set-top box from hacking | Kaspersky official blog
How cybercriminals recruit household appliances, and how to keep malware and malicious proxies off your home network.
> The High Crime of “LMAO”: How Cops Are Treating Mass Surveillance As a Joke
Here's a riddle: Why did a Goshen Police Department officer search 6,474 automated license plate reader (ALPR) networks, representing data from 82,413 cameras, on May 7, 2025?  If your answer is "I don't know," it turns out you're 100% correct. The officer left the letters "idk" in the search field...
> Malicious Twitch Extension Exposes 31,000 Users' OAuth Tokens
Socket has discovered a Twitch browser extension forwarding users' OAuth tokens to a Russian bot service
> ⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits
AI keeps showing up in the wrong places. Attackers are using it to speed up exploits, test defenses, and automate more of the job. Some models are also crossing lines on their own. That is not a great combination. The rest of the week is more familiar: old bugs still working, fresh exploit chains,...
> Perfect-10 GitLab bug under attack days after patch lands
CISA confirms active exploitation as watchTowr spots miscreants probing internet-facing servers