[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (146 articles)

|

// AI-powered summary generated at 20:00

> New RefluXFS Linux flaw lets attackers gain root privileges
A nine-year-old race condition vulnerability in the Linux kernel's XFS filesystem, tracked as CVE-2026-64600, allows local attackers to overwrite protected files and gain root privileges. [...]
> AI Agents Now the Enterprises Fastest Growing Exposed Attack Surface
Sophos report warns that the rapid adoption of AI by businesses is leaving them vulnerable to a new source of cyber threats
> Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers
Cybersecurity researchers have shed light on a large-scale campaign that has turned compromised GitHub repositories into distributed attack infrastructure designed to target cPanel and WebHost Manager (WHM) instances. The activity involves malicious Packagist development versions spanning 10 packag...
> Gmail attachment size limit: How to send large files via email
Hit the Gmail attachment size limit? Learn the best ways to send large files via email for personal or business use.
> Millions of cars could be tracked and unlocked by a hidden security flaw
A hidden flaw in a dealer-installed car alarm could let attackers unlock vehicles and track their locations. Many owners don't know they have one.
> WhatsApp Web chats exposed by Adobe’s Acrobat extension flaw
HermeticReader is a now-patched vulnerability in Adobe's popular Acrobat Chrome extension that could have been used to spy on WhatsApp Web users.
> Months-long breach exposes South Korean diplomats’ personal data
South Korea’s Foreign Ministry has disclosed that attackers breached the Korea National Diplomatic Academy’s online education system, compromising personal data belonging to current and former ministry staff and diplomats stationed abroad. The Korea National Diplomatic Academy launched the online tr...
> End-to-End Encryption and “Going Dark”
New paper: “Encryption and Globalization 15 Years Later: End-to-End Encryption and the Third Round of the ‘Going Dark’ Debate“: Abstract: This Article updates and expands on 2012 research on encryption and globalization, analyzing what the authors call “Round 3” of the Going Dark Debate: the current...
> How to open an Excel file online for free
Need an Excel alternative or want to open an Excel file online without paying for more software? Here are some options.
> How to forward emails in Gmail, Outlook, Yahoo, and Proton Mail
Learn how to forward emails in Gmail, Outlook, Yahoo, and Proton to unify your inboxes. Only one of these can't technically scan your emails.
> Upbound Group Says Data Breach Led to $13 Million in Fraudulent Contract Losses
Hackers recently obtained non-sensitive customer information and other documents from the company. The post Upbound Group Says Data Breach Led to $13 Million in Fraudulent Contract Losses appeared first on SecurityWeek.
> Attackers exploit critical Check Point flaw to take over firewall management (CVE-2026-16232)
Attackers are exploiting a critical authentication bypass vulnerability (CVE-2026-16232) that affects Check Point Security Management and Multi-Domain Security Management, the management servers that push policy to Check Point security gateways (i.e., firewalls). “An unauthenticated attacker can obt...
> USN-8322-2: Apache Commons BeanUtils regression
USN-8322-1 fixed a vulnerability in Apache Commons BeanUtils. It was discovered that for Ubuntu 18.04 LTS, during the update preparation phase, a previous fix for CVE-2014-0114 and CVE-2019-10086 was incorrectly dropped. This update reintroduces the fix for CVE-2014-0114 and CVE-2019-10086. We apol...
> Chaos ransomware msaRAT hides its C2 channel inside a legitimate browser process
Cisco Talos has identified a Rust-based remote access trojan it attributes to the Chaos ransomware group, named msaRAT after four of the binding names left in the binary. The tool starts its own instance of Chrome or Edge on the victim machine and controls it through Chrome DevTools Protocol, a debu...
> Investigating Synology RAID: Reassembly & Logical Imaging With Atola TaskForce 2
Reconstruct Synology SHR and SHR-2 automatically, browse evidence before imaging, and acquire only the files you need with Atola TaskForce 2.
> New Dolphin X Stealer Employs AI Profiling to Prioritize Targets
Dolphin X is a new infostealer that uses AI to sort and rank victims, giving cybercriminals a faster way to identify lucrative targets
> ANCHOR-CI could fix 20 years of broken government-industry collaboration
The government spent the past two decades learning what private sector partners have always known: cyber resilience requires everyone in the room. ANCHOR-CI is proof that the lessons may finally stick. The post ANCHOR-CI could fix 20 years of broken government-industry collaboration appeared first o...
> Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel
The Chaos ransomware group uses new malware "msaRAT" that hijacks browsers. The malware doesn't communicate directly with C2 but connects through the browser. It enables arbitrary command execution while hiding the attacker's IP from victims via WebRTC over TURN.
> Preview: Cisco Talos at Black Hat USA 2026
Here’s some of the ways Talos is showing up at Black Hat, alongside our friends at Cisco and Splunk.
> Google Adds Selfie Video Recovery for Users Locked Out of Their Accounts
Google on Thursday announced a new way for users to sign-in to their accounts by letting them take a selfie video. The selfie for sign-in, per the tech giant, is another option on top of existing recovery methods to log in to an account, including an email address or a phone number. The idea is to...