[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (107 articles)

|

// AI-powered summary generated at 16:00

> Pokemon Gym : 19 600 comptes exposés
Fuite Pokemon Gym : 19 600 comptes de joueurs et joueuses, adresses IP et messages privés exposés.
> Beyond the Play Store: How Android threats really spread
Some threats never pass through the Play Store. Others arrive later in seemingly legitimate updates. Here's how Malwarebytes detects both.
> Your Best Analyst Shouldn’t Be a Person. It Should Be a Capability Everyone Can Summon.
Transform expert SOC analysis into an on-demand AI capability to empower all analysts and accelerate threat resolution.
> Hotel Wi-Fi Routers Compromised to Steal Corporate Login Credentials From Visitors
Researchers at ReliaQuest warned of widespread DNS poisoning attacks targeting the hospitality sector as part of a cyber espionage campaign
> ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link
Cybersecurity researchers have disclosed a critical vulnerability in OpenAI's ChatGPT Workspace Agents that could have allowed a single phishing link to stealthily build, authorize, and deploy an autonomous artificial intelligence (AI) agent inside a victim's organization. The vulnerability has bee...
> Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers
A crafted SVG submitted to Bing's image search ran commands as NT AUTHORITY\SYSTEM on Microsoft's production image-processing workers, and as root on the Linux machines in the same fleet. XBOW's testing got the same result on workers across different hosts and network ranges, so the problem sat in...
> Infosec News Nuggets — July 24, 2026
China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks Group-IB uncovered an exposed Alibaba Cloud server tied to a China-linked operation dubbed JadeProx, revealing a previously undocumented Windows loader called TriBack that was used against government, healthcare, and e...
> Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do
AI agent security is moving through a familiar maturity curve: adoption, then visibility, and finally, control. But what we've collectively discovered is that enforcing least privilege for AI agents is harder than we ever imagined. This is why there are so many approaches, from prompt filtering to i...
> Forensic Focus Digest, July 24 2026
Explore the impact of cumulative trauma on digital forensic investigators, faster triage with ADF Pro, feature-phone recovery using MSAB XRY Pro, and Katelyn Rogers’ Chip ID Framework and SpecTacular.
> Industry Reactions to OpenAI Models Hacking Hugging Face: Feedback Friday
Industry professionals debate whether it represents a lab containment failure or an unprecedented agentic capability milestone. The post Industry Reactions to OpenAI Models Hacking Hugging Face: Feedback Friday appeared first on SecurityWeek.
> Man gets six years for hacking 750 women's Snapchat accounts
An Illinois man was sentenced on Tuesday to 76 months in prison and three years of supervised release for hacking the Snapchat accounts of over 750 women to steal nude photos. [...]
> ChatGPT Among Top 10 Most Impersonated Brands in Phishing Attacks, Says Check Point
OpenAI’s chatbot tool ChatGPT ranked among the top 10 most impersonated brands in phishing attacks for the first time
> Why AI Needs a “Genie Coefficient”
This essay was written with Barath Raghavan, and originally appeared in The Guardian. Major benchmarks measure what AI can do. None measure whether it does what you mean: the distance between what you ask an AI to do and the unspoken assumptions about how you want the AI to do it. We propose a new m...
> Top AIs invent same fake PyPl and npm package names
Enterprise software developers continue to be in danger of falling victim to slopsquatting, where AI coding tools hallucinate the existence of nonexistent libraries and hackers create malicious packages in response. The top AI coding tools are remarkably consistent in their...
> USN-8610-1: Linux kernel (Azure CVM) vulnerabilities
Maxim Suhanov discovered that the NTFS file system implementation in the Linux kernel did not properly validate file name length in certain situations, leading to an out-of-bounds read. An attacker could use this to construct a malicious NTFS image that, when mounted and operated on, could expose se...
> Motherless : les serveurs saisis au cœur de l’enquête
La police saisit les serveurs du site pour adultes Motherless dans une enquête européenne sur des contenus vidéos criminels.
> USN-8575-3: Linux kernel vulnerabilities
Maxim Suhanov discovered that the NTFS file system implementation in the Linux kernel did not properly validate file name length in certain situations, leading to an out-of-bounds read. An attacker could use this to construct a malicious NTFS image that, when mounted and operated on, could expose se...
> USN-8609-1: Linux kernel (Azure CVM) vulnerabilities
It was discovered that some AMD processors did not properly clear data in the floating point divider unit during speculative execution. A local attacker could use this to expose sensitive information. (CVE-2025-54505) It was discovered that some AMD Zen 2 processors did not properly isolate shared...
> Tycoon2FA takedown reshapes the phishing landscape
Traditional phishing techniques are in decline as a result of the disruption of the Tycoon2FA phishing-as-a-service (PHaaS) platform, Microsoft said in a new report, “Email threat landscape: Q2 2026 trends and insights”. “Phishing volume linked to the platform fell 92% from...
> USN-8608-1: Linux kernel (Azure FIPS) vulnerabilities
It was discovered that some AMD processors did not properly clear data in the floating point divider unit during speculative execution. A local attacker could use this to expose sensitive information. (CVE-2025-54505) It was discovered that some AMD Zen 2 processors did not properly isolate shared...