[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (146 articles)

|

// AI-powered summary generated at 20:00

> German law enforcement claims to have ‘dismantled’ mega phishing-as-a-service group Kratos
A global law enforcement crackdown has seized infrastructure serving the massive phishing-as-a-service (PhaaS) group Kratos, as well resulting in the arrest of an unnamed Kratos “developer and technical administrator” in Indonesia.  The effort was managed by German law enfo...
> OpenAI scored an own goal with HuggingFace attack, showing how open Chinese models are winning
Closed models with guardrails can still cause harm, but may also not be able to fix problems they caused
> Smashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hacker
A Russian intelligence-linked hacker is arrested in Thailand while enjoying a beach holiday - and the trail of evidence that nailed him to the Russian government includes 14 separate orders of chicken McNuggets. Meanwhile, AI music generator Suno has been hacked - and the stolen data appears to s...
> Swiss train maker Stadler refuses Everest $12 million ransomware demand
Stadler Rail said it will not make a $12.3 million ransom payment after cybercriminals stole technical data from a supplier's file-sharing platform.
> The Fourth Circuit Says Border Agents Can Search Your Phone By Hand, No Suspicion Required
Legal intern Suzanne Castillo was the principal author of this post. The Fourth Circuit issued a disappointing opinion in U.S. v. Belmonte Cardozo, a case in which EFF filed an amicus brief, alongside the national ACLU, its Maryland, North Carolina, South Carolina, and Virginia affiliates, and the N...
> CVE-2026-8933: Ubuntu security flaw breaks Snap sandbox protections
Qualys disclosed CVE-2026-8933, a high-severity Ubuntu flaw that lets local attackers gain root privileges through a race condition in snap-confine. Qualys has disclosed a high-severity local privilege escalation vulnerability, tracked as CVE-2026-8933 (CVSS score of 7.8), affecting default installa...
> Debian BIND9 Important Cache Poisoning Denial of Service DSA-6395-1
Debian released a security advisory for BIND9 highlighting multiple vulnerabilities that could lead to DNSSEC validation bypass and other security issues, urging users to upgrade to the latest version.
> Upbound says hack caused $13 million in fraudulent Acima leases
The Upbound Group fintech company disclosed that threat actors who stole data from its systems leveraged it to create $13 million in Acima leases. [...]
> Adobe Acrobat Chrome extension bug enabled silent WhatsApp data theft
Adobe patched CVE-2026-48294, a flaw in Adobe Acrobat Chrome extension that could let attackers steal WhatsApp Web chats by luring users to a webpage. Guardio Labs researcher Shaked Biner disclosed HermeticReader, a vulnerability chain in the Adobe Acrobat Chrome extension that allowed any attacker-...
> Debian Firefox ESR Important Code Execution Risks DSA-6394-1
Debian's advisory DSA-6394-1 highlights multiple vulnerabilities in firefox-esr, urging users to upgrade to version 140.13.0esr-1~deb13u1 to mitigate risks such as code execution and privilege escalation.
> Most federal cybersecurity reporting rules are duplicative, study finds
The Government Accountability Office looked at 117 rules across 37 agencies and found 70% had reporting requirements that were overlapping. The post Most federal cybersecurity reporting rules are duplicative, study finds appeared first on CyberScoop.
> Extension of CISA 2015 info-sharing protections passes as part of House’s defense bill
A 10-year renewal of the cybersecurity information-sharing law known as CISA 2015 passed as part of the House's fiscal 2027 defense authorization bill.
> USN-8591-1: AIOHTTP vulnerabilities
Sean Gilligan discovered that AIOHTTP did not properly limit memory usage when processing HTTP headers and trailers. An attacker could possibly use this issue to consume excessive system resources, resulting in a denial of service. (CVE-2026-22815) It was discovered that AIOHTTP did not properly li...
> Médias et blogs
Le Parlement français a adopté une loi visant à interdire l'accÚs aux services de réseaux sociaux en ligne aux mineurs de moins de quinze ans.Adoptée le 21 juillet, cette loi impose aux plateformes de réseaux sociaux d'interdire l'accÚs à leurs services aux mineurs de moins de 15 ans. La définition...
> IDPC - autorité maltaise
La Cour de justice de l'Union europĂ©enne a jugĂ© que la publication en ligne des noms d'athlĂštes professionnels ayant enfreint les rĂšgles antidopage peut ĂȘtre compatible avec le droit de l'Union, Ă  condition qu'une mise en balance des intĂ©rĂȘts soit possible avant la publication et que le principe de...
> Critical Zimbra security update fixes 9 vulnerabilities
Business email and collaboration suite Zimbra has received a major security update that fixes several critical issues that could allow attackers to execute malicious code on the server or in users’ browsers. Available in commercial and open-source editions, Zimbra Collabora...
> ICO - autorité britannique
L'autorité britannique de protection des données (ICO) a publié une série de rapports et de recherches portant sur les perceptions du public et les enjeux liés aux nouvelles technologies.Un rapport conjoint avec le Centre pour l'intelligence collective (CCI) de Nesta, financé par le Département pour...
> CNIL
La Commission Nationale de l'Informatique et des Libertés (CNIL) a organisé un webinaire pour présenter sa recommandation sur les pixels de suivi aux fournisseurs et prestataires de services.Ce webinaire, qui s'est tenu le 4 juin 2026, ciblait spécifiquement les entreprises proposant des services de...
> South Korea discloses data breach impacting diplomats worldwide
South Korea disclosed that hackers breached the National Diplomatic Academy's online education system for ten months and stole personal information belonging to current and former employees of the Ministry of Foreign Affairs (MFA), including overseas diplomats. [...]
> UODO - autorité polonaise
L'autorité polonaise de protection des données (UODO) a organisé une conférence portant sur les interactions entre le RGPD, la directive NIS2 et le systÚme national de cybersécurité (KSC).Le 20 juillet, une conférence organisée par l'autorité polonaise de protection des données (UODO) a réuni prÚs d...