[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (146 articles)

|

// AI-powered summary generated at 20:00

> How Google phone number verification works, and whether you should turn it off | Kaspersky official blog
Why and how Google checks your phone number, and the potential privacy risks involved.
> Ubuntu 26.04 Tar Important Directory Injection Fix USN-8477-3
USN-8477-1 introduced a regression in tar
> Japanese food logistics giant recovers as extortion group claims cyberattack
Nichirei Logistics Group said warehouse operations and frozen food shipments are returning to normal. A cybercrime gang said it caused the disruption.
> How enterprise GenAI can amplify ransomware risk — and how to contain it
Enterprise AI can accelerate ransomware attacks when AI assistants and agents inherit excessive permissions or compromised identities. Acronis explains how identity controls, governance, and least-privilege access help reduce AI-enabled ransomware risk while supporting secure AI adoption. [...]
> If you pay a hacker’s ransom, chances are that they’ll come back for more
The long-held understanding among security researchers and network defenders is that it's impossible to negotiate in good faith with an extortion racket because there's no incentive for the other side to actually walk away.
> USN-8477-3: tar regression
USN-8477-1 fixed a vulnerability in tar. That fix was incomplete and could cause tar to fail to extract old archives that recorded a nonzero size for directory entries, resulting in a regression. This update fixes the problem. We apologize for the inconvenience. Original advisory details: It was...
> Suno, Paidwork Data Breaches Affect Tens of Millions of Accounts
Hackers leaked names, email addresses, phone numbers, passwords, and financial information stolen from the two platforms.  The post Suno, Paidwork Data Breaches Affect Tens of Millions of Accounts appeared first on SecurityWeek.
> Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data
Cybersecurity researchers have disclosed details of a now-patched vulnerability chain in the Adobe Acrobat Chrome extension that has over 314 million users, which, if exploited, could facilitate a silent hijack of a user's WhatsApp data. The shortcoming has been codenamed HermeticReader by Guardio...
> From Triage Grind to Strategic Operator: The New AI SOC Career Path
Learn how AI is reshaping SOC careers, elevating analysts from manual triage to strategic threat hunting and AI governance.
> TrickBot Ditches HTTP for DNS Tunneling in Latest Variant
New TrickBot variant hides C2 communication inside DNS queries, replacing decade-old HTTP pattern
> Palo Alto Networks to Acquire Observability Platform Provider Embrace
Acquisition follows January's Chronosphere deal, deepening Palo Alto Networks' push beyond core security into observability. The post Palo Alto Networks to Acquire Observability Platform Provider Embrace appeared first on SecurityWeek.
> OpenAI: Our models breached Hugging Face during a cyber capability test
The recent Hugging Face breach was the work of several OpenAI models, the AI research company claimed in a blog post. The breach Late last week, the company behind Hugging Face, a platform that enables users to share machine learning models and datasets, said some of its internal datasets had been a...
> Ubuntu libgphoto2 Important Buffer Abuse Denial of Service Vuln 8586-1
Several security issues were fixed in libgphoto2.
> Ubuntu 26.04 GIFLIB Critical Denial of Service 2026-23868
GIFLIB could be made to crash or run programs if it opened a specially crafted file.
> Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft
An attacker only needed to convince the targeted user to visit a malicious website to exfiltrate WhatsApp messages and contacts. The post Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft appeared first on SecurityWeek.
> Ubuntu 26.04 LTS Kerberos Important DoS Issues USN-8585-1 CVE-2026-11850
Several security issues were fixed in Kerberos.
> Digital Forensics Round-Up, July 22 2026
Read the latest DFIR news – SQLite tips for mobile analysts, serverless forensics, Signal database decoding, AI image detection in iLEAPP and ALEAPP, Linux timeline tooling, macOS triage updates, and more.
> New InfraTrust report reveals infrastructure flaws admins should patch first
Eclypsium has launched InfraTrust, a new infrastructure cybersecurity knowledge base and monthly InfraTrust Pulse report designed to help organizations prioritize vulnerabilities affecting infrastructure, firmware, networking, and edge devices. [...]
> Intercepting Android WebView traffic under new certificate validity requirement by Chromium
In a recent security assessment, we were unable to intercept the traffic originating from a WebView from an Android application. The application wasn’t using certificate pinning, nor was it configured in any special way that would prevent normal interception. When testing that same application on a...
> OpenAI Presence connects AI agents to enterprise data with built-in guardrails
OpenAI has introduced Presence, a product designed to help companies deploy AI agents that handle customer support and internal service requests across voice and chat. (Source: OpenAI) The company describes Presence as a deployment platform rather than a standalone model. “Presence brings together t...