[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (1 articles)

|

// AI-powered summary generated at 04:00

> ZDI-26-459: GIMP SGI File Parsing Integer Overflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs ar...
> ZDI-26-458: GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs ar...
> Your AI agents can reach data no one approved
A credential expired. An AI agent kept using it anyway, and a mid-sized company’s systems went down for a quarter’s worth of trouble before anyone traced the failure back to a non-human account no one had been logging. That agent could reach customer records, source code, and HR files the whole time...
> ZDI-26-457: GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs ar...
> ZDI-26-456: GIMP TIF File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs ar...
> Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js
Beta release versions of two npm packages in the @joyfill namespace have been compromised to deliver a remote access trojan (RAT) associated with the DEV#POPPER malware family. The list of affected packages is as follows - @joyfill/[email protected] @joyfill/[email protected]...
> ZDI-26-455: GIMP TIF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs ar...
> ZDI-26-454: GIMP PSD File Parsing Integer Overflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs ar...
> Android malware detection collapses when the context stage comes out
A phone backup app asks for storage, contacts, SMS, and call logs. A device-management tool asks for more than that. Run either one past a machine learning malware scanner and it comes back flagged. Six Android detectors in wide research use, including Drebin, MalScan, and MaskDroid, produced that r...
> ZDI-26-453: GIMP HDR File Parsing Integer Overflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs ar...
> FTC sues Hims & Hers for allegedly sharing patient information with third-party platforms
Popular telehealth provider Hims & Hers "shared consumers’ sensitive health information with third-party advertising platforms such as Meta and Snap despite promising to protect patient privacy," the federal government alleges.
> America bans imported robots due to supply chain and security risks
Docs point to China’s Unitree as prime example of the foreign clanker threat
> ISC Stormcast For Wednesday, July 29th, 2026 https://isc.sans.edu/podcastdetail/10028, (Wed, Jul 29th)
> Measuring LLMs’ Ability to Perform Cryptanalysis
There’s new benchmark measuring AI’s ability to perform mathematical cryptanalysis. Anthropic’s frontier model actually found new attacks. The benchmark: “CryptanalysisBench: Can LLMs do Cryptanalysis?” The idea is to benchmark the ability of LLMs to discover new mathematical cryptanalytic attacks a...
> Slackware Samba Important DoS LDAP Issues Fix SSA-2026-209-03
New Samba packages addressing multiple security vulnerabilities are available for Slackware 15.0 and -current. Users are advised to upgrade and restart the service if running.
> Slackware Seamonkey Security Fix 2026-209-02 for Version 15.0
New SeaMonkey packages for Slackware 15.0 and -current are available, addressing security issues with version 2.53.24. Users can download the updated packages from designated Slackware repositories.
> Fortinet’s new FortiGate platform converges firewall, SASE technologies
Fortinet has expanded its firewall family with new high-speed boxes that, when combined with the vendor’s FortiSASE Outpost software, extend cloud-based SASE (secure access service edge) capabilities and policy enforcement to on-premises environments. The new midrange Forti...
> Slackware Libarchive Security Update Announcement for 2026-209-01
New libarchive packages for Slackware 15.0 and -current address security issues, providing an upgrade to version 3.8.9 with bug fixes and minor features.
> A 13-year-old flaw is exposing tens of thousands of data center management systems
The ‘no man’s land’ beneath the OS on enterprise servers is becoming the malicious actors’ next target. Attackers are gaining a foothold into broader data center environments by exploiting Baseboard Management Controllers (BMCs) that are largely unprotected, still running d...
> The CSO’s blind spot: Why platform engineering 2.0 is now a security imperative
Security leaders have spent the last decade building controls around people and code. Shift-left practices caught vulnerabilities earlier in the development cycle. Zero trust reduced lateral blast radius. Developer tooling added guardrails at the IDE. The architecture was soun...