[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (1 articles)

|

// AI-powered summary generated at 04:00

> Universidade de Aveiro
L'Université de Aveiro (UA) a détecté un accès non autorisé à ses systèmes d'information, entraînant l'exposition de données personnelles et institutionnelles. Le recteur a informé la communauté académique de cet incident et a demandé à tous les membres de changer leurs mots de passe, tout en recomm...
> No time to lose: Why post-quantum security for financial services must start now
Post-quantum cryptography: The emerging threatThe transition to post-quantum cryptography (PQC) is becoming an urgent priority for the global financial sector due to the rapid evolution of quantum computing. Cryptographically relevant quantum computers exist only as research prototypes. However, the...
> A Typo Landed an Innocent Gamer in Prison for 18 Months
How much could a single underscore in a username really matter? Just ask Brandon Klayme, who served 18 months in prison before realizing how authorities arrested, charged, and convicted the wrong man.
> Senate confirms Clayton as intel chief after delays
A party-line vote in the Senate installed Jay Clayton as director of national intelligence, a job that has drawn increasing scrutiny during Donald Trump's second term as president.
> MCP gets an enterprise makeover
Now happier running in a conventional K8s environment, with `an easier-to-live-with lifecycle
> Chromium: CVE-2026-13037 Use after free in WebView
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
> Chromium: CVE-2026-13030 Uninitialized Use in GPU
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
> Looks like JFrog's 0-days let OpenAI's models hack Hugging Face
The vendor won't confirm or deny
> Chromium: CVE-2026-13028 Use after free in WebGL
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
> Chromium: CVE-2026-13032 Use after free in WebGL
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
> San Francisco: Don’t Fall for Industry Defense of Surveillance Pricing
The concept of “surveillance pricing” is just one part of a much larger problem and business model: corporations maximizing their profits by invading our privacy. The all-too-common business model is to systematically harvest, collate, and store as much of our personal data as possible, and then mon...
> CubePilot drone software dev hit by DNS hijacking to intercept traffic
CubePilot, an Australian firm that designs flight controllers for drones (UAVs), announced a severe operational disruption caused by a DNS hijacking attack. [...]
> Here’s what Anthropic found when it turned Mythos loose on encryption algorithms
Claude Mythos exposed mathematical weaknesses in a post-quantum candidate and a simplified version of AES, marking a major breakthrough for AI-driven cryptanalysis. The post Here’s what Anthropic found when it turned Mythos loose on encryption algorithms appeared first on CyberScoop.
> OpenAI models used Artifactory zero-days to escape to the internet
JFrog has confirmed that OpenAI models exploited zero-day vulnerabilities in self-hosted Artifactory servers to help escape an isolated testing environment and gain access to the internet before attacking Hugging Face. [...]
> Microsoft and Wiz mind-meld agents catch more than 90% of bugs
Secret to their success: Using the right model for the right security job
> Dysphoria Botnet Uses Blockchain Domains to Hide C2 Infrastructure
Researchers uncovered the 200,000-device Dysphoria botnet, which uses Ethereum and Solana domains to hide its command servers. QiAnXin XLab, jointly with China’s CNCERT, disclosed Dysphoria, a botnet that has compromised roughly 200,000 devices worldwide and uses Ethereum and Solana blockchain domai...
> Ubuntu FreeRDP RDP Client Significant Clipboard Regression Fix USN-8561-2
A regression affecting clipboard functionality in FreeRDP was introduced in an earlier security update. Users should update to resolve the issue in Ubuntu 26.04 LTS and 24.04 LTS.
> Coordinated cyberattack disrupts water utilities in 30+ Minnesota communities
A cyberattack of undetermined origin disrupted water treatment plants in at least 30 communities in Minnesota, according to the state's technology bureau. The post Coordinated cyberattack disrupts water utilities in 30+ Minnesota communities appeared first on CyberScoop.
> Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack
Anthropic says Claude Mythos Preview helped derive an end-to-end key-recovery attack against HAWK-256 and a 200- to 800-fold speedup for an attack on seven-round AES-128. The HAWK attack exploits a previously unused symmetry in the lattice behind the signature scheme. Anthropic's released implement...
> AWS KMS or AWS CloudHSM: Choose the right key management solution
Choosing the right cryptographic key management service on Amazon Web Services (AWS) starts with understanding the difference between AWS Key Management Service (AWS KMS) and AWS CloudHSM. Both provide key storage backed by a hardware security module (HSM) but serve very different needs. AWS KMS is...