[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> CVE-2026-64191 i2c: stub: Reject I2C block transfers with invalid length
Information published.
> CVE-2026-39879 SQL injection in syslog-ng SQL destionation driver
Information published.
> Police dismantle Kratos phishing platform behind 15,000 monthly campaigns
German and US law enforcement have dismantled the infrastructure behind Kratos, a notorious phishing-as-a-service (PhaaS) platform. Its alleged developer and administrator was arrested in Indonesia by local police. Seizure banner (Source: BKA) The takedown was led by the Frankfurt public prosecutor’...
> CVE-2026-26197 Array full size, element count, and element size are not checked to make sure they match in H5Odtype.c
Information published.
> CVE-2026-64192 bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized
Information published.
> OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face 
The admission comes days after Hugging Face disclosed an attack powered by autonomous AI agents.  The post OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face  appeared first on SecurityWeek.
> CVE-2026-26199 Buffer underflow in `H5Iget_name `/`H5G_get_name` if size is zero
Information published.
> CVE-2026-64187 xfs: fail recovery on a committed log item with no regions
Information published.
> 10 survival tips for CSOs who report to the CEO
As the CSO grows in prominence, security leaders are increasingly earning a seat at the executive table, reporting directly to the CEO with the expectation to help drive business strategy and ensure organizational success. Reporting to the CEO unlocks greater access and inf...
> CVE-2026-64205 i2c: i801: fix hardware state machine corruption in error path
Information published.
> CVE-2026-64190 net: team: fix NULL pointer dereference in team_xmit during mode change
Information published.
> Chick-fil-A discloses data breach after credential stuffing attacks
American fast food restaurant chain Chick-fil-A is notifying customers of a data breach after their accounts were hacked in a wave of recent credential stuffing attacks. [...]
> CVE-2026-64206 Bluetooth: L2CAP: cancel pending_rx_work before taking conn->lock
Information published.
> Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA
German and US law enforcement have taken down the core infrastructure of Kratos, described by German investigators as one of the world's most widely used criminal phishing kits, and Indonesian authorities arrested the man they say developed and ran it. In a joint announcement on Monday, the Frankfu...
> OneDrive et SharePoint : les captures d’écran des PDF sensibles bientôt bloquées
Microsoft va bloquer les captures d'écran des PDF étiquetés « Ne pas autoriser la capture d'écran » dans OneDrive et SharePoint, uniquement via Microsoft Edge. Le post OneDrive et SharePoint : les captures d’écran des PDF sensibles bientôt bloquées a été publié sur IT-Connect.
> Suno : un piratage révèle le pillage de YouTube et Deezer pour entraîner son IA
Un piratage de Suno a exposé le code de son scrapping massif : plus de deux millions d'extraits YouTube Music, des heures de Deezer, Genius, Pond5 et plus. Le post Suno : un piratage révèle le pillage de YouTube et Deezer pour entraîner son IA a été publié sur IT-Connect.
> Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library
Cybersecurity researchers have discovered a NuGet typosquat that's unlike the typical information-stealing malware distributed via package registries: usual info-stealers: it's designed to rig live game results on Digitain. The package, named "Newtonsoftt.Json.Net," masquerades as the Newtonsoft.Js...
> Small teams are the heaviest users of AI coding agents
The pull request arrives with the tests already run and the description already written, the work of an agent that handled the whole thing on its own. Somebody still has to read it. On GitHub that somebody is usually one developer sitting alone with the diff, and the rest of the project never sees t...
> Snowpick: Open-source ServiceNow exposure scanner
An employee opens a company service portal, searches the knowledge base, and drops a file onto a ticket. Someone who never signed in can send a request to that same portal and get records back. Bishop Fox ran that test across 166 ServiceNow instances during authorized penetration tests. The firm pub...
> OpenAI says its AI models hacked Hugging Face during testing
OpenAI says its AI models, including GPT‑5.6 Sol and a pre-release model, hacked into the Hugging Face artificial intelligence repository while being tested in a sandboxed testing environment. [...]