[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (146 articles)

|

// AI-powered summary generated at 20:00

> South Korea discloses data breach impacting diplomats worldwide
South Korea disclosed that hackers breached the National Diplomatic Academy's online education system for ten months and stole personal information belonging to current and former employees of the Ministry of Foreign Affairs (MFA), including overseas diplomats. [...]
> Federal agencies broaden alert on Iran-linked OT attacks
The observed incidents include “malicious project file interactions and manipulation of data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays,” the advisory says.
> How OpenAI’s human mistake led to the AI-powered hack on Hugging Face
OpenAI made a mistake setting up what it called a “highly isolated” testing environment and sandbox. According to cybersecurity experts, that human mistake is what made the AI-powered attack on Hugging Face possible.
> GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier
Beginning July 27, 2026, GitHub will cut public bug bounty payouts by at least half at every severity level. Critical findings will drop from $20,000-$30,000+ to a fixed $10,000, while its permanent invite-only VIP tier will pay $30,000 or more. Reports filed before that date, including those alrea...
> Oracle’s July update fixes ten 10.0 vulnerabilities in Fusion Middleware
Oracle’s July 2026 Critical Patch Update, its largest ever, contains 1,449 new security patches spanning 32 product families, from Oracle Database and E-Business Suite to PeopleSoft, GoldenGate, Java SE, and Fusion Middleware. Fusion Middleware was particularly hard hit, wi...
> Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs
Cybersecurity researchers have disclosed details of a new local privilege escalation (LPE) vulnerability in snap-confine that an unprivileged user can trigger to obtain root access and gain complete control of a target environment. The high-severity flaw, tracked as CVE-2026-8933 (CVSS score: 7.8),...
> French Parliament greenlights social media ban for under-15s
Both houses of the French Parliament voted to block social media access for children under 15, making France the first European country to enact a ban amid a broadening global crackdown.
> Ubuntu 26.04 LTS Exim Important File Access and Priv Escalation USN-8590-1
Several security issues were fixed in Exim.
> Rondo Meets Geoserver, (Wed, Jul 22nd)
This isn&#;x26;#;39;t a new attack, but something I saw "pop-up" in our logs this week:
> Malware is targeting AI tools in software development environments
The worm blends in with thousands of other commands occurring daily in any given environment, yet its intent and origins remain unknown. The post Malware is targeting AI tools in software development environments appeared first on CyberScoop.
> Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack
Swiss rail vehicle manufacturer Stadler Rail says the Everest ransomware gang demanded about $12.3 million after breaching a data exchange platform shared with one of its suppliers. [...]
> Linux kernel team publishes 432 CVEs in two days
Sunday-to-Monday onslaught fuels speculation over AI-assisted bug reports
> USN-8590-1: Exim vulnerabilities
It was discovered that Exim incorrectly handled certain command line options. A local attacker could possibly use this issue to access files outside of the spool area. It was discovered that Exim incorrectly handled string expansion in .local files. A local attacker could possibly use this issue to...
> Cisco’s new AI model tells code reviewers where to look for vulnerabilities
Cisco has revealed a family of open-weight AI models called Antares that, it said, can help security teams isolate potentially vulnerable parts of a software repository before deeper investigation begins. Rather than detecting a specific CVE or generating a patch, these mod...
> New Kimsuky campaign compromised South Korean software vendors
A North Korean advanced persistent threat (APT) group recently targeted vendors of collaborative-work software, South Korean researchers said.
> White House accuses Chinese company of distilling Anthropic’s Fable
While distillation attacks by foreign governments and companies have real national security implications, questions around who ultimately owns the data in AI systems are fraught. The post White House accuses Chinese company of distilling Anthropic’s Fable appeared first on CyberScoop.
> USN-8589-1: Apache HTTP Server vulnerabilities
It was discovered that Apache HTTP Server's mod_ldap module incorrectly handled memory when processing per-directory configurations. A remote attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-29167) It was discovered that Apache HTTP Server's m...
> Is Passwork safe for your business?
An investigation found that Spanish password manager Passwork didn't disclose its ties to Russia. Here's what your business needs to know.
> USN-8588-1: Gawk vulnerabilities
It was discovered that Gawk incorrectly handled memory when processing input using the getline redirection. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-40467) It was discovered that Gawk incorrectly handled certain integer calculations when allocating memory. A...
> Real world incident response: Microsoft and AXA XL strengthen cyber resilience
Our collaboration with AXA XL brings Microsoft Incident Response services directly to cyber insurance policyholders, helping organizations coordinate technical, business, and insurance decisions. The post Real world incident response: Microsoft and AXA XL strengthen cyber resilience appeared first o...