[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (146 articles)

|

// AI-powered summary generated at 20:00

> Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs
RefluXFS, a new Linux kernel flaw disclosed on July 22 and tracked as CVE-2026-64600, lets an unprivileged local user overwrite root-owned files on an XFS filesystem and gain persistent root access. Qualys said default installations of Red Hat Enterprise Linux and its derivatives, Fedora Server, an...
> CVE-2026-55990 Packet of death for a DNSCrypt misconfigured Unbound
Information published.
> CVE-2026-50046 Possible heap use-after-free in an error path when a DoT forwarded query is jostled out
Information published.
> Two-Thirds of Ransomware Victims Say AI Boosted Attack Effectiveness
A new study of organizations which have fallen victim to ransomware suggests the rise of AI-tools being used by hackers is making life harder for defenders
> CVE-2026-42955 Extra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records disallowing a one-time 'ghost domain' delegation renewal via glue records
Information published.
> CVE-2026-46582 A wildcard replay, as another piece of data, triggers poisoning in the serve expired reply path
Information published.
> USN-8595-1: Linux kernel (Oracle) vulnerabilities
It was discovered that some AMD processors did not properly clear data in the floating point divider unit during speculative execution. A local attacker could use this to expose sensitive information. (CVE-2025-54505) It was discovered that some AMD Zen 2 processors did not properly isolate shared...
> CVE-2026-32665 Remote DNS-over-QUIC denial of service due to `quic-size` budget bypass
Information published.
> CVE-2026-40691 Packet of death for DNSCrypt over TCP
Information published.
> USN-8574-2: Linux kernel vulnerabilities
It was discovered that some AMD processors did not properly clear data in the floating point divider unit during speculative execution. A local attacker could use this to expose sensitive information. (CVE-2025-54505) It was discovered that some AMD Zen 2 processors did not properly isolate shared...
> CVE-2026-55717 'serve-expired-client-timeout' and 'response-ip' CNAME redirect could lead to a crash
Information published.
> CVE-2026-44621 Libunbound applications configured with 'unwanted-reply-threshold' could eventually be abruptly terminated
Information published.
> USN-8594-1: Linux kernel (OEM) vulnerabilities
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Foo-over-UDP (FOU); - ARM64 architecture; - x86 architecture; - Block layer subsystem; - Drivers core; - N...
> CVE-2026-55708 Privacy/configuration issue when adding local data in views through 'unbound-control'
Information published.
> CVE-2026-50248 BOGUS configured primary hostname accepted for XFR in auth/rpz zones
Information published.
> USN-8593-1: Linux kernel vulnerabilities
It was discovered that some AMD Zen 2 processors did not properly isolate shared resources in the operation cache. A local attacker could possibly use this issue to corrupt instructions executed at a higher privilege level, resulting in privilege escalation. (CVE-2025-54518) Several security issues...
> CVE-2026-44687 Off-by-one error in 'harden-below-nxdomain' logic can shadow a stub/forward zone by a legitimate parent's NXDOMAIN
Information published.
> CVE-2026-55973 'dns-error-reporting: yes' leads to stack buffer overflow
Information published.
> Axonius expands Asset Cloud with Cyber Assets and Exposures enhancements
Axonius has announced new capabilities across the Axonius Asset Cloud to better address asset intelligence and exposure management use cases. The enhancements make it easier than ever to address CMDB visibility gaps and respond to vulnerabilities, while extending asset intelligence capabilities to I...
> CVE-2026-56145 Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service
Information published.