[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (107 articles)

|

// AI-powered summary generated at 16:00

> USN-8603-1: Linux kernel (Azure) vulnerabilities
It was discovered that some AMD processors did not properly clear data in the floating point divider unit during speculative execution. A local attacker could use this to expose sensitive information. (CVE-2025-54505) It was discovered that some AMD Zen 2 processors did not properly isolate shared...
> Ransomware Attacks Targeting Universities on the Rise
Comparitech’s analysis of incidents in the first half of 2026 finds that the emergence of The Gentlemen ransomware has resulted in surge in attacks against higher education
> Google gives developers an AI bug hunter that also writes patches
Google has launched a preview of CodeMender, an AI agent built to scan code for security flaws, confirm they are exploitable, and generate fixes for developers to review. (Source: Google) The company describes it as a response to attackers who are already using AI to speed up their work, arguing tha...
> The AI Trust Paradox: Businesses Are Racing Ahead, but Consumers Are Hesitating
Artificial intelligence adoption is soaring, but consumer trust lags. Transparency, human oversight, and clear AI use cases are key to closing the trust gap. Businesses are rapidly adopting AI, with 93% planning deployment, but consumer trust lags far behind: only 23% trust companies to use AI with...
> Bento : une alternative open source Ă  PowerPoint qui tient dans un seul fichier HTML
Bento est une alternative open source à PowerPoint : un fichier HTML de 570 Ko qui embarque l'éditeur, le mode présentateur, les données et la collaboration. Le post Bento : une alternative open source à PowerPoint qui tient dans un seul fichier HTML a été publié sur IT-Connect.
> Google’s newest sign-in method asks you to look at the camera
Google’s selfie video sign-in option verifies that an account owner is a real person and that the account wasn’t created or used by computer programs or bots for the purpose of abuse, such as spamming. It is not available for all regions, accounts, or devices. Source: Google A selfie video is record...
> US Agencies Warn of Laundry Bear Campaign Targeting Unpatched Zimbra Servers
US agencies warn Russian group Laundry Bear is exploiting a patched Zimbra flaw to steal email accounts from organizations running unpatched servers. The Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), Federal Bureau of Investigation (FBI) and other U.S. gove...
> CVE-2026-64600 xfs: resample the data fork mapping after cycling ILOCK
Information published.
> CVE-2026-59677 Process Kill Attack Vector in killall() in seunshare
Information published.
> NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats
Eight security flaws in NodeBB went public on Wednesday, along with the code to exploit them. Aikido Security rates all eight as high severity and says its AI pentest agents found them in a six-hour review of the forum software's source code. Every version before 4.14.0 is affected. NodeBB has fixe...
> CVE-2026-59676 Local File Deletion Attack Vector in rm_rf() in seunshare
Information published.
> Clop ransomware targets Windchill, FlexPLM in data theft attacks
The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign. [...]
> SharedRoot : l’agent IA de Claude Cowork peut s’évader de sa VM et lire vos fichiers
Des chercheurs ont fait sortir l'agent IA de Claude Cowork de sa machine virtuelle pour lire et écrire sur le Mac hôte. Anthropic n'a pas publié de correctif. Le post SharedRoot : l’agent IA de Claude Cowork peut s’évader de sa VM et lire vos fichiers a été publié sur IT-Connect.
> Ransomware groups are hammering your vulnerable VPNs
Cybercriminals are actively exploiting a recently discovered vulnerability in Palo Alto Networks firewall and VPN appliances to deploy the Qilin ransomware strain. A critical authentication bypass flaw (CVE-2026-0257) in Palo Alto GlobalProtect portal and gateway was the co...
> Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say
Redis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0. All four chains require RESTORE. The Streams chains also need EVAL and XGROUP; the 8.8.0 chain needs EVAL and the bundled RedisBloom module. Redis say...
> Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign that involves the use of a malicious program that's dressed up as a Notepad++ plugin to compromise Windows systems. The activity has been attributed by the agency to a threat cluster it tracks as UAC-0099, a Russ...
> The automotive software vulnerabilities hiding in your dashboard
Pop the hood on a new car and you won’t find much you can fix with a wrench. What you’ll find is software, and a lot of it. The screen in the dash probably runs Android or a flavor of Linux. The system watching the road for you might run QNX or VxWorks, the same kind of code that flies aircraft and...
> Governing Al agents at scale: Lessons from the leaders who’ve done it
Enterprise AI leaders from ZoomInfo, Docusign and AppViewX share what it took to build AI Centers of Excellence and govern agent identities inside two companies operating at scale. What you’ll take away: What an AI Center of Excellence looks like day to day at ZoomInfo and Docusign How to govern age...
> Data Breach Confirmed After Australian Energy Giant Origin Is Hacked
A hacker claims to have stolen the information of 2 million Origin Energy customers and is threatening to leak it.  The post Data Breach Confirmed After Australian Energy Giant Origin Is Hacked appeared first on SecurityWeek.
> Thunderbird 153 : nouvelle version ESR, support Exchange natif et 61 failles corrigées
Thunderbird 153 Meadow inaugure la nouvelle branche ESR : gestionnaire de comptes remanié, Exchange via EWS, DNS over HTTPS et 61 failles corrigées. Le post Thunderbird 153 : nouvelle version ESR, support Exchange natif et 61 failles corrigées a été publié sur IT-Connect.