[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (1 articles)

|

// AI-powered summary generated at 04:00

> ISC Stormcast For Wednesday, July 29th, 2026 https://isc.sans.edu/podcastdetail/10028, (Wed, Jul 29th)
> Measuring LLMs’ Ability to Perform Cryptanalysis
There’s new benchmark measuring AI’s ability to perform mathematical cryptanalysis. Anthropic’s frontier model actually found new attacks. The benchmark: “CryptanalysisBench: Can LLMs do Cryptanalysis?” The idea is to benchmark the ability of LLMs to discover new mathematical cryptanalytic attacks a...
> Slackware Seamonkey Security Fix 2026-209-02 for Version 15.0
New SeaMonkey packages for Slackware 15.0 and -current are available, addressing security issues with version 2.53.24. Users can download the updated packages from designated Slackware repositories.
> Slackware Samba Important DoS LDAP Issues Fix SSA-2026-209-03
New Samba packages addressing multiple security vulnerabilities are available for Slackware 15.0 and -current. Users are advised to upgrade and restart the service if running.
> Fortinet’s new FortiGate platform converges firewall, SASE technologies
Fortinet has expanded its firewall family with new high-speed boxes that, when combined with the vendor’s FortiSASE Outpost software, extend cloud-based SASE (secure access service edge) capabilities and policy enforcement to on-premises environments. The new midrange Forti...
> Slackware Libarchive Security Update Announcement for 2026-209-01
New libarchive packages for Slackware 15.0 and -current address security issues, providing an upgrade to version 3.8.9 with bug fixes and minor features.
> A 13-year-old flaw is exposing tens of thousands of data center management systems
The ‘no man’s land’ beneath the OS on enterprise servers is becoming the malicious actors’ next target. Attackers are gaining a foothold into broader data center environments by exploiting Baseboard Management Controllers (BMCs) that are largely unprotected, still running d...
> The CSO’s blind spot: Why platform engineering 2.0 is now a security imperative
Security leaders have spent the last decade building controls around people and code. Shift-left practices caught vulnerabilities earlier in the development cycle. Zero trust reduced lateral blast radius. Developer tooling added guardrails at the IDE. The architecture was soun...
> OpenAI’s Rogue AI Agent Hacked More Than Just Hugging Face
In a new disclosure, OpenAI says its agent used exposed logins to gain access to at least four “publicly available services” in its unhinged quest to solve a test.
> Arista patches maximum severity vulnerability that is already being exploited
Arista has patched a VeloCloud Orchestrator (VCO) security hole that has been actively leveraged in the wild, one that the vendor says “may allow a remote attacker to access privileged internal functionality and impact the VCO host.” The Arista security advisory added that...
> Cyera agrees to acquire Oasis Security for $1B to safeguard proliferating AI agents
The deal is Cyera's third acquisition this year.
> Multiples vulnérabilités dans Microsoft Edge (29 juillet 2026)
De multiples vulnérabilités ont été découvertes dans Microsoft Edge. Elles permettent à un attaquant de provoquer une atteinte à l'intégrité des données et un problÚme de sécurité non spécifié par l'éditeur.
> Vulnérabilité dans Apache Tomcat (29 juillet 2026)
Une vulnérabilité a été découverte dans Apache Tomcat. Elle permet à un attaquant de provoquer un déni de service à distance.
> Secure by Design in practice: a year of progress on Sophos Firewall
One year on from our last Secure by Design update, we’re changing the format: deeper, per-product updates. First up: the firewall.
> Multiples vulnérabilités dans Citrix XenServer (29 juillet 2026)
De multiples vulnérabilités ont été découvertes dans Citrix XenServer. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et un problÚme de sécurité non spécifié par l'éditeur.
> Multiples vulnérabilités dans Xen (29 juillet 2026)
De multiples vulnérabilités ont été découvertes dans Xen. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilÚges, un déni de service à distance et une atteinte à la confidentialité des données.
> Administrația Națională a Penitenciarelor (ANP)
L'administration pénitentiaire de roumaine (ANP) a été victime d'une cyberattaque de type ransomware le 29 juillet 2026. L'équipe informatique de l'ANP a contacté immédiatement le Bureau National de Sécurité Cybernétique (DNSC), qui est intervenu rapidement pour limiter l'impact en isolant physiquem...
> Beacon CRM
Beacon CRM, une plateforme de gestion de données utilisée par diverses organisations culturelles, a été victime d'une cyberattaque impliquant un accÚs non autorisé temporaire à ses systÚmes. L'incident, découvert le 29 juillet, a entraßné la copie potentielle de sauvegardes de bases de données. Les...
> Lights on! Real-time threat response with Red Hat Advanced Cluster Security
Part 2 of a series on implementing zero trust in Red Hat OpenShift with the layered zero trust validated pattern (ZTVP)In our previous article, we explored why network policies, specifically a default-deny posture combined with strict ingress and egress rules, are your critical last line of defense...
> Mistertemp' group
Mistertemp' group, un groupe français de recrutement et de travail temporaire, a confirmé avoir été victime d'un incident de sécurité informatique le 29 juillet 2026. Cet incident a entraßné un accÚs non autorisé à certaines données personnelles, incluant le nom, le prénom, l'adresse e-mail, le numé...