[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (107 articles)

|

// AI-powered summary generated at 16:00

> US Agencies Warn of Laundry Bear Campaign Targeting Unpatched Zimbra Servers
US agencies warn Russian group Laundry Bear is exploiting a patched Zimbra flaw to steal email accounts from organizations running unpatched servers. The Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), Federal Bureau of Investigation (FBI) and other U.S. gove...
> CVE-2026-64600 xfs: resample the data fork mapping after cycling ILOCK
Information published.
> CVE-2026-59677 Process Kill Attack Vector in killall() in seunshare
Information published.
> NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats
Eight security flaws in NodeBB went public on Wednesday, along with the code to exploit them. Aikido Security rates all eight as high severity and says its AI pentest agents found them in a six-hour review of the forum software's source code. Every version before 4.14.0 is affected. NodeBB has fixe...
> CVE-2026-59676 Local File Deletion Attack Vector in rm_rf() in seunshare
Information published.
> Clop ransomware targets Windchill, FlexPLM in data theft attacks
The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign. [...]
> SharedRoot : l’agent IA de Claude Cowork peut s’évader de sa VM et lire vos fichiers
Des chercheurs ont fait sortir l'agent IA de Claude Cowork de sa machine virtuelle pour lire et écrire sur le Mac hôte. Anthropic n'a pas publié de correctif. Le post SharedRoot : l’agent IA de Claude Cowork peut s’évader de sa VM et lire vos fichiers a été publié sur IT-Connect.
> Ransomware groups are hammering your vulnerable VPNs
Cybercriminals are actively exploiting a recently discovered vulnerability in Palo Alto Networks firewall and VPN appliances to deploy the Qilin ransomware strain. A critical authentication bypass flaw (CVE-2026-0257) in Palo Alto GlobalProtect portal and gateway was the co...
> Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say
Redis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0. All four chains require RESTORE. The Streams chains also need EVAL and XGROUP; the 8.8.0 chain needs EVAL and the bundled RedisBloom module. Redis say...
> Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign that involves the use of a malicious program that's dressed up as a Notepad++ plugin to compromise Windows systems. The activity has been attributed by the agency to a threat cluster it tracks as UAC-0099, a Russ...
> The automotive software vulnerabilities hiding in your dashboard
Pop the hood on a new car and you won’t find much you can fix with a wrench. What you’ll find is software, and a lot of it. The screen in the dash probably runs Android or a flavor of Linux. The system watching the road for you might run QNX or VxWorks, the same kind of code that flies aircraft and...
> Governing Al agents at scale: Lessons from the leaders who’ve done it
Enterprise AI leaders from ZoomInfo, Docusign and AppViewX share what it took to build AI Centers of Excellence and govern agent identities inside two companies operating at scale. What you’ll take away: What an AI Center of Excellence looks like day to day at ZoomInfo and Docusign How to govern age...
> Data Breach Confirmed After Australian Energy Giant Origin Is Hacked
A hacker claims to have stolen the information of 2 million Origin Energy customers and is threatening to leak it.  The post Data Breach Confirmed After Australian Energy Giant Origin Is Hacked appeared first on SecurityWeek.
> Thunderbird 153 : nouvelle version ESR, support Exchange natif et 61 failles corrigées
Thunderbird 153 Meadow inaugure la nouvelle branche ESR : gestionnaire de comptes remanié, Exchange via EWS, DNS over HTTPS et 61 failles corrigées. Le post Thunderbird 153 : nouvelle version ESR, support Exchange natif et 61 failles corrigées a été publié sur IT-Connect.
> Ransomware gangs go after EMEA healthcare’s supply chain
A ransomware attack against a hospital makes headlines, while attacks on the rest of the ecosystem around it tend to stay quiet despite doing damage that can be just as bad. Flare researcher Assaf Morag analyzed ransomware leak-site activity tied to healthcare organizations in the EMEA region betwee...
> Un écran LG branché, et Windows installe une pub McAfee : Microsoft a tranché
Brancher un moniteur LG suffisait à installer une application qui affichait des pubs McAfee. Microsoft est intervenu, LG désactive le pop-up. Explications. Le post Un écran LG branché, et Windows installe une pub McAfee : Microsoft a tranché a été publié sur IT-Connect.
> The best-funded companies open the most phishing attachments
An employee gets an email dressed as a password reset. She clicks the link, types her credentials into a page built to copy her company’s login screen, and moves on with her morning. She tells no one. That silence is the exposure. Across 13.9 million simulated phishing messages, one in ten recipient...
> Ransomware in 2026: More groups, more victims, no slowdown
Ransomware activity followed a recognizable pattern during the previous four years. Each year was defined by a dominant actor, its collapse, or a major supply chain incident. Black Kite’s 2026 Ransomware Report documents a more fragmented market, with multiple ransomware playbooks scaling at the sam...
> ISC Stormcast For Friday, July 24th, 2026 https://isc.sans.edu/podcastdetail/10022, (Fri, Jul 24th)
> New infosec products of the week: July 24, 2026
Here’s a look at the most interesting products from the past week, featuring releases from Astelia, Druva, Swimlane, and ThreatDown. Druva brings backup, recovery and governance to AI workloads Druva has announced Druva AI Resilience, a new approach that helps organizations recover, govern, and defe...