[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (19 articles)

|

// AI-powered summary generated at 08:00

> Grafana Assistant expands with AI agents for investigations, automation, and observability
Grafana Labs has announced the general availability of six AI capabilities, extending Grafana Assistant into an agentic operations layer that detects, investigates, and remediates production issues. The releases include Grafana Assistant Investigations, Grafana Assistant Workspace, Grafana Assistant...
> NVIDIA’s Open Secure AI Alliance Is Missing Some Big Names
NVIDIA has launched a new Open Secure AI Alliance to build an “open defense stack for agents”
> New Crypter-as-a-Service Cruciferra Fuels Stealthy Malware Attacks Worldwide
Proofpoint uncovered Cruciferra, a crypter-as-a-service that helps hackers evade antivirus and deliver malware in multiple campaigns. Proofpoint’s research team traced a wave of income-tax-themed lures targeting Indian taxpayers, tax professionals, and corporate finance teams back to a crypter servi...
> AWS to retire Shield Advanced L7 automatic mitigation on January 1, 2027
AWS Shield Advanced, a managed service that protects applications from external threats, is adding the Anti-DDoS managed rule group, designed for application-layer (L7) DDoS protection, to eligible web access control lists (ACLs) in Count mode. The addition preserves traffic flow and runs alongside...
> Suitable AI : 15 176 comptes exposés via GraphQL
Suitable AI : une fuite revendiquée expose 15 176 candidats et des failles critiques à grande échelle.
> Arista patches actively exploited VeloCloud bug as CISA puts admins on the clock
Unauthenticated command injection scores perfect 10 and may expose managed Edge devices
> Data breach at medical billing firm MCBS affects 1.26 million people
Healthcare billing company Medical Computer Business Services (MCBS) has disclosed that a 2025 network breach exposed the sensitive information of more than 1.2 million people. [...]
> KomikoAI : une fuite relie courriels et prompts
Des données personnelles d'un professionnel de l'IA piratés : courriels, identifiants, contenus générés et prompts d’utilisateurs.
> Coca-Cola confirms hackers stole data in Fairlife ransomware attack
Coca-Cola has confirmed that the ransomware attack on its dairy subsidiary Fairlife involved the theft of company data, weeks after the incident temporarily halted production at its US facilities. Fairlife is a Coca-Cola-owned dairy brand that makes ultra-filtered milk and protein drinks, with annua...
> Why your AI safety certificates are worthless at runtime
Every week, another enterprise technology vendor issues a glossy press release announcing their new autonomous AI agent architecture, complete with a SOC 2 Type II report, an ISO 42001 certification, and an ironclad safety guarantee. On paper, the enterprise security battle lo...
> New CREST AI Standards to Deliver AI-Enabled Pentesting Accreditation
CREST’s new AI standards are optional add-on requirements for cybersecurity service providers wishing to demonstrate responsible AI usage
> Google Adopts New Threat Actor Naming System
The new two-word naming convention uses a memorable term utilized in public reporting and a cluster-categorization word. The post Google Adopts New Threat Actor Naming System appeared first on SecurityWeek.
> U.S. CISA adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Arista VeloCloud Orchestrator and Fortinet FortiOS flaws t...
> Ils piratent le Wi-Fi des hĂ´tels pour siphonner les comptes Microsoft 365
Des passerelles Wi-Fi d'hôtels sont détournées pour empoisonner le DNS et rediriger les voyageurs vers de faux portails Microsoft 365. Attention à ces attaques. Le post Ils piratent le Wi-Fi des hôtels pour siphonner les comptes Microsoft 365 a été publié sur IT-Connect.
> Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In
JetBrains is urging customers of on-premise versions of TeamCity to update to the latest version following the discovery of a critical security issue that could result in arbitrary code execution. The vulnerability, assigned CVE-2026-63077 (CVSS score: 9.8), affects all TeamCity On-Premises version...
> Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit
STAR Labs has published a Linux kernel exploit that turns an ordinary local user into root on the CentOS Stream 9 build it targeted. The flaw, tracked as CVE-2026-53264 (CVSS score: 7.8), is a use-after-free race in the kernel's network traffic-control subsystem.Researcher Lee Jia Jie said artificia...
> Hugging Face breach shows why incident response needs a multi-model AI strategy
The recent breach of Hugging Face’s platform was the latest in a string of AI-assisted intrusions to come to light in recent weeks, showing that attackers can now use LLMs to automate entire attack chains. But it also exposed a limitation for defenders trying to use AI to resp...
> Ubuntu 24.04 AWS Kernel Important Security Issues Fix USN-8595-3
Ubuntu has released security updates addressing vulnerabilities in the Linux kernel for versions 22.04 LTS and 24.04 LTS, requiring immediate user action for system updates.
> Ubuntu 22.04 Linux Kernel Critical Privilege Escalation Vulnern 2025-8619-1
Ubuntu 22.04 LTS was updated to fix multiple vulnerabilities in the Linux kernel, particularly affecting AMD processors, which could lead to information exposure and privilege escalation.
> AutoIT Payload Injector , (Tue, Jul 28th)
For a long time, AutoIT[1] has been pretty common in the malware ecosystem. Threat actors still use it because it's easy to write and powerful. Indeed, it can perform all the required actions to inject a payload into a remote process as you'll see below.