[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (107 articles)

|

// AI-powered summary generated at 16:00

> CVE-2026-56160 Azure Red Hat OpenShift (ARO) Elevation of Privilege Vulnerability
Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.
> CVE-2026-54120 Microsoft Surface Remote Code Execution Vulnerability
Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.
> Abstract Raises $25 Million to Expand Composable Security Operations Platform
The latest investment round brings the total raised by Abstract to nearly $50 million. The post Abstract Raises $25 Million to Expand Composable Security Operations Platform appeared first on SecurityWeek.
> CVE-2026-56165 Microsoft Account Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.
> CVE-2026-56163 Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
> When the "Autonomous Attacker" Is Your Own AI Model, (Thu, Jul 23rd)
Two disclosures, five days apart, described the same intrusion from opposite ends —
> CVE-2026-56167 Azure AI Search Elevation of Privilege Vulnerability
Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.
> Iranian Hackers Target Siemens and Schneider Industrial Systems, CISA Warns
US government agencies have warned that Iranian cyber actors are targeting US-based Siemens and Schneider industrial equipment
> Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files
Cybersecurity researchers have uncovered a sandbox escape vulnerability in Anthropic's Claude Cowork that makes it possible to break out of the confines of a Linux virtual machine (VM) within which the agent runs to read or write files anywhere on the Mac. Accomplish AI, which shared details of the...
> What to look for in a secure cloud workspace (before you commit)
Here's how to evaluate security, data sovereignty, and lock-in risk before you commit to a new cloud workspace.
> Major Australian energy supplier confirms customer data compromised
Origin Energy said it was working to figure out how many Australians were affected by a recent data breach.
> Infosec News Nuggets — July 23, 2026
Check Point Warns of SmartConsole Zero-Day Exploited in Attacks  Check Point patched CVE-2026-16232, an authentication bypass vulnerability in its SmartConsole GUI admin panel that allows unauthenticated attackers to obtain an application login token usable to authenticate with administrator privile...
> How attackers hosted a fake Claude download page on the claude.ai domain
A threat actor abused Anthropic’s Claude Artifacts feature to funnel users toward malware, Huntress researchers have disclosed. Employees at at least 29 organizations were compromised over two days in July, after searching for the Claude desktop app and clicking a sponsored Bing ad. The ad pointed t...
> Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge
The Chaos ransomware group ran its command-and-control through the victim's own browser. Cisco Talos on Thursday detailed msaRAT, the Rust implant behind it, found on a compromised Windows machine ahead of the encryptor. The implant never opens an outbound connection of its own. Its process talks t...
> One ChatGPT link could smuggle a rogue AI agent into your company
Researchers say OpenAI flaw let phishing bait create an autonomous corporate mole armed with employee access
> Mount Here, Read There: Twin Path Traversal CVEs in Kubernetes Storage
Discover how a filepath.Join misconception caused cross-tenant path traversal vulnerabilities in Kubernetes CSI drivers.
> Cobalt adds Autonomous Pentest to scale application security testing
Cobalt has introduced Cobalt Autonomous Pentest, a new offering that enables continuous offensive security across an organization’s application portfolio by delivering actionable penetration testing results in as little as 24 hours. AI-assisted development enables organizations to ship software fast...
> Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models
SentinelOne’s new benchmark, built on the Fast16 case, shows which AI models can sustain a malware investigation and which cannot. The post Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models appeared first on SecurityWeek.
> Ubuntu 16.04 Apache Commons BeanUtils Critical Regression Fix USN-8322-2
A regression was introduced in Apache Commons BeanUtils affecting Ubuntu 16.04 LTS due to an incomplete fix for CVE-2014-0114 and CVE-2019-10086, which could allow arbitrary code execution.
> EU fines Google $1 billion for search, app store antitrust violations
The European Commission fined Google €890 million ($1 billion) on Thursday after finding the company had violated the European Union's Digital Markets Act (DMA), which ensures fair online competition. [...]