[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (51 articles)

|

// AI-powered summary generated at 12:01

> CVE-2024-14040 net: nexthop: Increase weight to u16
Information published.
> GitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package Adoption
GitHub has announced a new cooldown mechanism in Dependabot, allowing the tool to wait at least three days after a release is published before opening a pull request. "The cooldown configuration option in the dependabot.yml still controls the behavior, though, so you can choose a different cooldown...
> Google goes it alone with a new cybercrime crew taxonomy
So much for Microsoft and CrowdStrike’s plans for consistent names across the industry
> A week in security (July 20 – July 26
A list of topics we covered in the week of July 20 to July 26 of 2026
> How CISOs can rise to the business resilience challenge
CISOs have quietly become their organizations’ de facto chief resilience officers as the role has evolved from its primary prevention roots to now include greater emphasis on incident response and business resiliency and recovery. “Any experienced CISO who’s come up through...
> Dolphin X : ce nouvel infostealer utilise l’IA pour trier ses victimes
Dolphin X est un malware voleur de données compatible Windows qui vise plus de 300 applications et embarque un AI Profiler pour trier les victimes. Le post Dolphin X : ce nouvel infostealer utilise l’IA pour trier ses victimes a été publié sur IT-Connect.
> HTTP Message Signatures with curl
The recently published RFC 9421 describes how to do HTTP Message Signatures, and starting just now, curl experimentally supports them. Message Signatures The specification describes this as a mechanism for creating, encoding, and verifying digital signatures or message authentication codes over comp...
> Marathon Petroleum’s CISO on OT security automation, supply chain risk
In this interview with Help Net Security, Mary Rose Martinez, CISO at Marathon Petroleum, talks about what happens to security when automation reaches deep into refineries, pipelines, and terminals. She explains why the old idea of air-gapped operational technology has faded, how the Purdue model he...
> LockBit5 and Qilin Lead Ransomware Attacks Against Italian Organizations
A new report links 148 ransomware attacks to Italian organizations in H1 2026, with manufacturing the most targeted sector. Six months, 148 confirmed ransomware claims against Italian targets, and one sector taking the brunt of it. That’s the headline number from a new semi-annual tracker compiled b...
> RefluXFS : cette faille dans XFS donne un accès root sur RHEL, CentOS et AlmaLinux
RefluXFS (CVE-2026-64600) est une faille du système de fichiers XFS qui permet à un utilisateur local de devenir root sur RHEL. Ce qu'il faut savoir. Le post RefluXFS : cette faille dans XFS donne un accès root sur RHEL, CentOS et AlmaLinux a été publié sur IT-Connect.
> Nono: Open-source sandbox for AI agents
An AI coding agent opens a terminal, reads a config file, and finds a live cloud key sitting in plaintext. It runs with the permissions of the person who launched it. Every file that person can read, the agent reads. Every credential in the environment, the agent can use. That reach is where the dam...
> 5 High-Impact Use Cases for Falcon Onum
> What the identity attack surface looks like when trust becomes the target
In this Help Net Security video, Joel Moses, VP, Strategic Engineering at F5, explains how attackers use identity instead of breaking through it. He walks through MFA fatigue, session token theft, and consent given to malicious applications, using the 2022 Uber breach as an example. He also covers h...
> MCBS Data Breach Affects 1.2 Million Individuals
The PEAR ransomware group claimed to have stolen 3 TB of information from the medical business management company. The post MCBS Data Breach Affects 1.2 Million Individuals appeared first on SecurityWeek.
> Product showcase: LastPass Authenticator brings Face ID, Apple Watch, and cloud backup to 2FA
LastPass Authenticator is a free app that provides two-factor authentication (2FA) for accounts and any service that supports time-based one-time passwords (TOTP). It supports push notifications for one-tap approvals and generates six-digit verification codes for online accounts. The app is availabl...
> CrowdStrike Joins the Open Secure AI Alliance to Advance AI Safety and Security
> GitHub delays version updates so malware gets caught first
An automated update tool watches a package registry, catches a new release the moment it publishes, and opens a pull request for your team. That is the job it was built to do. In September 2025, that speed cut the wrong way. An attacker phished one npm maintainer’s credentials and shipped poisoned v...
> ISC Stormcast For Monday, July 27th, 2026 https://isc.sans.edu/podcastdetail/10024, (Mon, Jul 27th)
> Columbus Water Works
Columbus Water Works a été victime d'une cyberattaque le 27 juillet qui a affecté une partie de ses systèmes de surveillance automatisés. Bien que les opérateurs aient dû passer immédiatement au contrôle manuel, l'approvisionnement en eau et la qualité de l'eau potable n'ont pas été interrompus ni a...
> Strengthening the open source defense layer: Red Hat joins NVIDIA in the Open Secure AI Alliance
As AI capabilities advance, they transform the security landscape in real time. To address these challenges at scale, no single company can act in isolation. We must bring together our respective expertise across the industry. That is why Red Hat is proud to participate as an inaugural member of the...