[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (19 articles)

|

// AI-powered summary generated at 08:00

> U.S. CISA adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Arista VeloCloud Orchestrator and Fortinet FortiOS flaws t...
> Ils piratent le Wi-Fi des hôtels pour siphonner les comptes Microsoft 365
Des passerelles Wi-Fi d'hôtels sont détournées pour empoisonner le DNS et rediriger les voyageurs vers de faux portails Microsoft 365. Attention à ces attaques. Le post Ils piratent le Wi-Fi des hôtels pour siphonner les comptes Microsoft 365 a été publié sur IT-Connect.
> Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In
JetBrains is urging customers of on-premise versions of TeamCity to update to the latest version following the discovery of a critical security issue that could result in arbitrary code execution. The vulnerability, assigned CVE-2026-63077 (CVSS score: 9.8), affects all TeamCity On-Premises version...
> Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit
STAR Labs has published a Linux kernel exploit that turns an ordinary local user into root on the CentOS Stream 9 build it targeted. The flaw, tracked as CVE-2026-53264 (CVSS score: 7.8), is a use-after-free race in the kernel's network traffic-control subsystem.Researcher Lee Jia Jie said artificia...
> Hugging Face breach shows why incident response needs a multi-model AI strategy
The recent breach of Hugging Face’s platform was the latest in a string of AI-assisted intrusions to come to light in recent weeks, showing that attackers can now use LLMs to automate entire attack chains. But it also exposed a limitation for defenders trying to use AI to resp...
> Ubuntu 24.04 AWS Kernel Important Security Issues Fix USN-8595-3
Ubuntu has released security updates addressing vulnerabilities in the Linux kernel for versions 22.04 LTS and 24.04 LTS, requiring immediate user action for system updates.
> Ubuntu 22.04 Linux Kernel Critical Privilege Escalation Vulnern 2025-8619-1
Ubuntu 22.04 LTS was updated to fix multiple vulnerabilities in the Linux kernel, particularly affecting AMD processors, which could lead to information exposure and privilege escalation.
> AutoIT Payload Injector , (Tue, Jul 28th)
For a long time, AutoIT[1] has been pretty common in the malware ecosystem. Threat actors still use it because it's easy to write and powerful. Indeed, it can perform all the required actions to inject a payload into a remote process as you'll see below.
> Ubuntu 20.04 Linux Kernel Alert USN-8620-1 CVE-2023-45896 High Risk
Ubuntu 20.04 LTS has received a security update addressing multiple vulnerabilities in the Linux kernel, enhancing protection against potential exploitations and requiring system restarts after installation.
> Ubuntu Linux Kernel Security Issues Severity Important USN-8570-2
Ubuntu 24.04 LTS addresses multiple vulnerabilities in the linux-oracle-6.17 kernel, requiring users to update their systems to enhance security and possibly recompile third-party kernel modules.
> USN-8620-1: Linux kernel vulnerabilities
Maxim Suhanov discovered that the NTFS file system implementation in the Linux kernel did not properly validate file name length in certain situations, leading to an out-of-bounds read. An attacker could use this to construct a malicious NTFS image that, when mounted and operated on, could expose se...
> Ubuntu Kernel USN-8574-3 Multiple Security Flaws Affecting System Integrity
Ubuntu's security update addresses multiple vulnerabilities in the Linux kernel for AMD processors, impacting versions 22.04 LTS and 24.04 LTS, enhancing system security against potential attacks.
> USN-8619-1: Linux kernel (HWE) vulnerabilities
It was discovered that some AMD processors did not properly clear data in the floating point divider unit during speculative execution. A local attacker could use this to expose sensitive information. (CVE-2025-54505) It was discovered that some AMD Zen 2 processors did not properly isolate shared...
> Unpatched Fastjson Vulnerability Exploited in Attacks
The critical remote code execution bug can be exploited without authentication, under the library’s stock default configurations. The post Unpatched Fastjson Vulnerability Exploited in Attacks appeared first on SecurityWeek.
> USN-8595-3: Linux kernel (AWS) vulnerabilities
It was discovered that some AMD processors did not properly clear data in the floating point divider unit during speculative execution. A local attacker could use this to expose sensitive information. (CVE-2025-54505) It was discovered that some AMD Zen 2 processors did not properly isolate shared...
> USN-8574-3: Linux kernel vulnerabilities
It was discovered that some AMD processors did not properly clear data in the floating point divider unit during speculative execution. A local attacker could use this to expose sensitive information. (CVE-2025-54505) It was discovered that some AMD Zen 2 processors did not properly isolate shared...
> Click to Pray : l’appli de prière du Pape a exposé les données de plus de 700 000 personnes
Une faille IDOR dans l'API de Click to Pray exposait les e-mails et dates de naissance de 719 517 comptes. Signalée en janvier, corrigée seulement en juillet. Le post Click to Pray : l’appli de prière du Pape a exposé les données de plus de 700 000 personnes a été publié sur IT-Connect.
> USN-8570-2: Linux kernel (Oracle) vulnerabilities
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Foo-over-UDP (FOU); - ARM64 architecture; - x86 architecture; - Block layer subsystem; - Drivers core; - N...
> USN-8618-1: Linux kernel vulnerabilities
It was discovered that some AMD Zen 2 processors did not properly isolate shared resources in the operation cache. A local attacker could possibly use this issue to corrupt instructions executed at a higher privilege level, resulting in privilege escalation. (CVE-2025-54518) Several security issues...
> IA – Codeberg veut bannir les projets vibe codés : 358 voix contre 144
La forge Git Codeberg a voté l'interdiction des projets majoritairement générés par IA. Crawlers, SSD à 3 700 euros, confiance : les raisons du basculement. Le post IA – Codeberg veut bannir les projets vibe codés : 358 voix contre 144 a été publié sur IT-Connect.