[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> CVE-2026-38755 A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.
Information published.
> CVE-2026-38754 A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.
Information published.
> Exploitation of ServiceNow Vulnerability Seen Days After Disclosure
The ServiceNow AI platform vulnerability tracked as CVE-2026-6875 can be exploited for remote code execution. The post Exploitation of ServiceNow Vulnerability Seen Days After Disclosure appeared first on SecurityWeek.
> Fuite revendiquée au Rassemblement national ?
Un pirate affirme vendre des données présumés volés au Rassemblement national qui révélerait des données internes, sans preuve publique permettant d’authentifier la fuite à ce stade.
> Open-source maintainers still work underfunded as sponsorship crosses $100 million
A maintainer patches a library late at night that ships inside thousands of products, and no invoice follows. Sebastián Ramírez and Caleb Porzio spent years in that position. Ramírez, known as tiangolo, builds tools that other Python projects depend on. Porzio built Livewire and Alpine.js, tools tho...
> Hugging Face frappé par un agent cyber autonome
Une attaque autonome contre Hugging Face révèle les risques cyber des pipelines de données et des agents IA.
> Zimbra Update Patches Critical Vulnerabilities
The latest Zimbra refresh resolves command injection, XSS, restriction bypass, and SSRF security defects. The post Zimbra Update Patches Critical Vulnerabilities appeared first on SecurityWeek.
> Windows LegacyHive zero-day flaw gets free, unofficial patches
Free unofficial patches are available for a recently disclosed Windows zero-day flaw that allows attackers to escalate privileges on up-to-date Windows systems. [...]
> CVE-2026-42770 FFC-DH Peer Validation Uses Attacker-Supplied q
Information published.
> CVE-2026-38752 A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.
Information published.
> New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack
Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, the AI-agent-driven operator it first documented earlier this month. The same operator has now been spotted deploying ENCFORGE, a new compiled Go ransomware designed to encrypt model weights, vector indexes...
> CVE-2026-38753 A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.
Information published.
> CVE-2026-64082 riscv: Fix register corruption from uninitialized cregs on error
Information published.
> Weekly Update 513: Clauding The Home Network
Presently sponsored by: CoreView: Misconfigurations in Microsoft 365 leave doors open. Scan your tenant for free?.I reckon this week's video on how Claude is tying together info from UniFi, Home Assistant and the Pi-Hole is an absolute ripper. Or at least the concept is - if ever there was an actual...
> CVE-2026-63974 Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close
Information published.
> CVE-2026-64146 erofs: fix metabuf leak in inode xattr initialization
Information published.
> HollowByte : une faille DoS dans OpenSSL corrigée en silence, sans CVE
La faille HollowByte sature la mémoire d'un serveur OpenSSL avec un paquet de 11 octets. Corrigée en silence depuis la version 4.0.1, et sans aucun CVE. Le post HollowByte : une faille DoS dans OpenSSL corrigée en silence, sans CVE a été publié sur IT-Connect.
> CVE-2026-63978 net/handshake: Drain pending requests at net namespace exit
Information published.
> CVE-2026-63999 ethtool: rss: fix indir_table and hkey leak on get_rxfh failure
Information published.
> The Hidden Privilege of Automation Platforms
Automation platforms such as n8n are often introduced as productivity tools: connect a few systems, automate repetitive work, maybe add some AI. Inside a corporate network, however, that framing is incomplete. A self-hosted workflow engine can reach internal systems, execute actions on behalf of use...