> TODAY'S SUMMARY (146 articles)
Today's cybersecurity landscape highlights several critical threats and vulnerabilities. The ShinyHunters hacking group is under scrutiny following the arrest of a suspect in the Netherlands and is actively exploiting a zero-day vulnerability in Oracle's PeopleSoft products. Additionally, over 16,000 misconfigured Supabase databases have been found exposing sensitive personal information. The U.S. CISA has issued warnings regarding two critical zero-day vulnerabilities in Citrix NetScaler products, which are currently under active exploitation. Meanwhile, a significant breach at the cryptocurrency exchange Bitget, involving $388 million, has been linked to a flaw in third-party security products. AI-related security concerns continue to grow, with reports of AI agents bypassing security controls, prompting firms like OpenAI to pause training on their models.
|
// AI-powered summary generated at 20:00
The Chaos ransomware gang is using a new backdoor dubbed msaRAT that hides command-and-control (C2) communication by routing it through the Chrome or Edge browsers. [...]
He replaces Guy Rosen, who announced his retirement from the company after 13 years.
The post Assaf Keren Appointed New CISO of Meta appeared first on SecurityWeek.
The Python Package Index (PyPI) now rejects uploads of new files to releases older than 14 days to prevent attackers from poisoning long-stable releases if a project’s publishing tokens or release workflows are compromised. “This change will protect Python users and reduce the amount of “cleanup” wo...
Microsoft is working to resolve an ongoing Exchange Online issue that has been mistakenly quarantining customers' mailboxes since Sunday. [...]
The vulnerability tracked as CVE-2026-16232 has been exploited against customers with certain configurations.
The post New Check Point Zero-Day Vulnerability Exploited in the Wild appeared first on SecurityWeek.
Microsoft va faire des passkeys la méthode par défaut dans Entra ID et retire l'authentification par SMS et appel vocal. Calendrier, impact et alternatives.
Le post Microsoft 365 : la fin de l’authentification MFA par SMS et appel au profit des passkeys a été publié sur IT-Connect.
Cybercriminal group Everest is demanding 10 million Swiss francs ($12.3 million) from Swiss rail vehicle manufacturer Stadler after breaching a data exchange platform shared with one of its suppliers through compromised credentials. Stadler operates 16 production and component plants and eight engin...
Cloudflare a analysé le trafic HTTP mondial pendant la Coupe du monde 2026. Décalage horaire, streaming, paris en ligne : voici ce que révèlent ses données.
Le post Coupe du monde 2026 : comment Cloudflare a vu le Mondial redessiner le trafic Internet a été publié sur IT-Connect.
En moins d'une semaine, Joshua Boniface, Anthony Lavado et Andrew Rabert ont quitté Jellyfin. Burn-out, code IA, gouvernance : ce que l'on sait.
Le post Open Source – Jellyfin : trois départs majeurs, entre burn-out et tensions autour de l’IA a été publié sur IT-Connect.
GitHub is changing its bug bounty program to reward higher-quality vulnerability reports and reduce low-effort submissions, including AI-generated reports. The changes will take effect on July 27, 2026. Reports submitted before that date will be honored under the previous bounty structure. “Alongsid...
La CVE-2026-8933 est une faille dans snap-confine qui donne à un utilisateur local un accès root sur Ubuntu. Voici comment se protéger.
Le post Accès root : une faille dans snap-confine expose les machines Ubuntu a été publié sur IT-Connect.
Ubuntu released a security notice addressing multiple vulnerabilities in the Linux kernel affecting Ubuntu 20.04 LTS, necessitating immediate updates and potential recompilation of third-party kernel modules.
Check Point addressed a critical authentication bypass flaw, tracked as CVE-2026-16232, in SmartConsole that is being actively exploited. Check Point has released security updates to fix multiple vulnerabilities, including CVE-2026-16232 (CVSS score of 9.3), a critical authentication bypass flaw aff...
Maxim Suhanov discovered that the NTFS file system implementation in the
Linux kernel did not properly validate file name length in certain
situations, leading to an out-of-bounds read. An attacker could use this to
construct a malicious NTFS image that, when mounted and operated on, could
expose se...
Ubuntu has released a security update fixing multiple vulnerabilities in the Linux kernel, affecting the NTFS file system and some AMD processors, requiring kernel recompilation for third-party modules.
Maxim Suhanov discovered that the NTFS file system implementation in the
Linux kernel did not properly validate file name length in certain
situations, leading to an out-of-bounds read. An attacker could use this to
construct a malicious NTFS image that, when mounted and operated on, could
expose se...
Ubuntu has released updates for its Linux kernel to address multiple security vulnerabilities affecting Ubuntu 20.04 and 22.04 LTS, requiring users to reboot after installation.
Maxim Suhanov discovered that the NTFS file system implementation in the
Linux kernel did not properly validate file name length in certain
situations, leading to an out-of-bounds read. An attacker could use this to
construct a malicious NTFS image that, when mounted and operated on, could
expose se...
Israeli cybersecurity firm Check Point Software has addressed an actively exploited zero-day flaw in the company's SmartConsole graphical user interface (GUI) admin panel. [...]
Ubuntu Security Notice USN-8596-1 details several security vulnerabilities in the Linux kernel affecting Ubuntu 22.04 and 24.04, requiring immediate system updates and potential recompilation of third-party modules.