[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (19 articles)

|

// AI-powered summary generated at 08:00

> Dysphoria Botnet Uses Blockchain Domains to Hide C2 Infrastructure
Researchers uncovered the 200,000-device Dysphoria botnet, which uses Ethereum and Solana domains to hide its command servers. QiAnXin XLab, jointly with China’s CNCERT, disclosed Dysphoria, a botnet that has compromised roughly 200,000 devices worldwide and uses Ethereum and Solana blockchain domai...
> Ubuntu FreeRDP RDP Client Significant Clipboard Regression Fix USN-8561-2
A regression affecting clipboard functionality in FreeRDP was introduced in an earlier security update. Users should update to resolve the issue in Ubuntu 26.04 LTS and 24.04 LTS.
> Coordinated cyberattack disrupts water utilities in 30+ Minnesota communities
A cyberattack of undetermined origin disrupted water treatment plants in at least 30 communities in Minnesota, according to the state's technology bureau. The post Coordinated cyberattack disrupts water utilities in 30+ Minnesota communities appeared first on CyberScoop.
> Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack
Anthropic says Claude Mythos Preview helped derive an end-to-end key-recovery attack against HAWK-256 and a 200- to 800-fold speedup for an attack on seven-round AES-128. The HAWK attack exploits a previously unused symmetry in the lattice behind the signature scheme. Anthropic's released implement...
> AWS KMS or AWS CloudHSM: Choose the right key management solution
Choosing the right cryptographic key management service on Amazon Web Services (AWS) starts with understanding the difference between AWS Key Management Service (AWS KMS) and AWS CloudHSM. Both provide key storage backed by a hardware security module (HSM) but serve very different needs. AWS KMS is...
> CISA shares advice on isolating vital systems during cyberattacks
The U.S. and Australian governments have released new guidance urging critical infrastructure organizations to prepare to isolate vital operational technology systems in the event of a cyberattack or other major disruptions. [...]
> vBulletin fixes critical pre-auth RCE flaw with public exploit
A critical vulnerability in the vBulletin forum software allows unauthenticated attackers to execute arbitrary PHP code through template rendering. [...]
> USN-8561-2: FreeRDP regression
USN-8561-1 fixed vulnerabilities in FreeRDP. Unfortunately, the upgrade to version 3.30.0 introduced a regression in the clipboard functionality. This update fixes the problem. We apologize for the inconvenience. Original advisory details: It was discovered that FreeRDP contained multiple securi...
> AEPD - autorité espagnole
L'autorité espagnole sanctionne un propriétaire à hauteur de 6 000 € pour l'installation d'un système de vidéosurveillance dans les parties communes d'un appartement loué, en l'absence de base légale valide.Faits et contexteL'autorité espagnole de protection des données (AEPD) a publié le 28 juillet...
> AEPD - autorité espagnole
L'autorité espagnole de protection des données (AEPD) a clos une procédure de sanction initiée pour traitement illicite de données, en application du principe interdisant une double sanction pour les mêmes faits (*non bis in idem*), après que la personne concernée a été condamnée au pénal.Faits et c...
> FBI sees Anthropic’s Mythos as a law enforcement challenge
The post FBI sees Anthropic’s Mythos as a law enforcement challenge appeared first on CyberScoop.
> GPDP - autorité italienne
L'autorité italienne de protection des données a infligé une amende de 2 000 000 € à un courtier en données américain pour avoir collecté et vendu illégalement les données de personnes en Italie, affirmant sa compétence sur la base du critère de suivi du comportement prévu par le RGPD.Faits et conte...
> 2026 Phase 1a IRAP report is now available on AWS Artifact for Australian customers
Amazon Web Services (AWS) is excited to announce that the latest version of Information Security Registered Assessors Program (IRAP) report (Phase 1a – full assessment) is now available through AWS Artifact. An independent Australian Signals Directorate (ASD) certified IRAP assessor completed the IR...
> Microsoft dégaine MAI-Cyber-1-Flash et Project Perception pour la cybersécurité
Microsoft dévoile MAI-Cyber-1-Flash, son premier modèle IA dédié à la cybersécurité, et Project Perception, ses agents rouges, bleus et verts. Le post Microsoft dégaine MAI-Cyber-1-Flash et Project Perception pour la cybersécurité a été publié sur IT-Connect.
> Cette faille dans le système d’antivol expose 2,2 millions de voitures, mais l’Europe est épargnée
Des chercheurs révèlent qu'une clé Bluetooth unique, partagée par tous les boîtiers antivol KARR et SWDS, ouvre l'accès à 2,2 millions de véhicules. Le post Cette faille dans le système d’antivol expose 2,2 millions de voitures, mais l’Europe est épargnée a été publié sur IT-Connect.
> Why Are Gay Bars Building Databases of Their Patrons?
Recent reports have raised alarm about the use of PatronScan, an ID-checking and face-scanning system, at multiple LGBTQ+ bars in San Francisco’s Castro neighborhood. Much of the attention has focused on reports that the system photographs patrons as they enter venues and questions about whether tho...
> Wordfence PRISM Detected Backdoored WordPress Plugin within Two Hours of it Being Introduced
On July 28th, 2026, our autonomous AI vulnerability intelligence agent, Wordfence PRISM, identified a critical Authentication Bypass backdoor in Advanced Responsive Video Embedder, a WordPress plugin with approximately 20,000 active installations, less than two hours after the malicious code was int...
> Debian hplip Important Escalation and Code Exec Risks DSA-6402-1
Debian addresses two vulnerabilities in hplip that could lead to privilege escalation or code execution, urging users to upgrade to the fixed version 3.22.10+dfsg0-8.1+deb13u1.
> Click to pray expose les données de plus de 700 000 fidèles
Click To Pray expose 700 000 comptes via une faille idiote, avec un risque élevé de phishing ciblé et d’usurpation.
> DEF CON bans Meta-style 'pervert glasses'
More organizers prohibit camera-equipped specs, even with prescription lenses