[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> CVE-2026-63959 usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT
Information published.
> CVE-2026-64138 ksmbd: validate SID in parent security descriptor during ACL inheritance
Information published.
> New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack
Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, the AI-agent-driven operator it first documented earlier this month. The same operator has now been spotted deploying ENCFORGE, a new compiled Go ransomware designed to encrypt model weights, vector indexes...
> CVE-2026-64097 drm/amd/display: Validate GPIO pin LUT table size before iterating
Information published.
> CVE-2026-64160 netfs: Fix potential for tearing in ->remote_i_size and ->zero_point
Information published.
> Weekly Update 513: Clauding The Home Network
Presently sponsored by: CoreView: Misconfigurations in Microsoft 365 leave doors open. Scan your tenant for free?.I reckon this week's video on how Claude is tying together info from UniFi, Home Assistant and the Pi-Hole is an absolute ripper. Or at least the concept is - if ever there was an actual...
> CVE-2026-64001 ALSA: pcm: oss: Fix setup list UAF on proc write error
Information published.
> CVE-2026-64079 netfilter: x_tables: allocate hook ops while under mutex
Information published.
> HollowByte : une faille DoS dans OpenSSL corrigée en silence, sans CVE
La faille HollowByte sature la mémoire d'un serveur OpenSSL avec un paquet de 11 octets. Corrigée en silence depuis la version 4.0.1, et sans aucun CVE. Le post HollowByte : une faille DoS dans OpenSSL corrigée en silence, sans CVE a été publié sur IT-Connect.
> CVE-2026-64036 cgroup/rstat: validate cpu before css_rstat_cpu() access
Information published.
> CVE-2026-64038 hwmon: (lm90) Stop work before releasing hwmon device
Information published.
> The Hidden Privilege of Automation Platforms
Automation platforms such as n8n are often introduced as productivity tools: connect a few systems, automate repetitive work, maybe add some AI. Inside a corporate network, however, that framing is incomplete. A self-hosted workflow engine can reach internal systems, execute actions on behalf of use...
> CVE-2026-64133 ALSA: asihpi: Fix potential OOB array access at reading cache
Information published.
> White hat hacker Park Chan-am zeros in on the AI era’s key security challenges
Dubbed the “Genius Hacker,” Park Chan-am began his white hat hacker journey at the precocious age of 11, winning awards at domestic and international hacking competitions since his teenage years. He has since served as a cybersecurity advisor for various Korean government a...
> Context bombing heralds a new AI era of deceptive defense
Attackers are increasingly using AI agents to automate all phases of cyberattacks, prompting the security industry and enterprises to find new network defense approaches. One technique that shows promise is to intentionally plant decoy files with prompts that trigger the conte...
> Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution
Threat actors are now exploiting a recently disclosed critical security flaw impacting ServiceNow AI Platform, according to Defused Cyber. In a post shared on X, the threat intelligence firm said it's observing in-the-wild exploitation of CVE-2026-6875 (CVSS score: 9.5), a sandbox escape vulnerabil...
> ESET Protect On-Prem version 13.1 has been released
ESET Protect On-Prem version 13.1.10.0 has been released.
> Attackers Exploit Critical ServiceNow RCE Flaw CVE-2026-6875
Attackers are exploiting critical ServiceNow flaw CVE-2026-6875, allowing unauthenticated remote code execution on self-hosted instances. Searchlight Cyber researchers disclosed a critical pre-authentication remote code execution vulnerability, tracked as CVE-2026-6875, in the ServiceNow AI Platform...
> The air gap is a myth and other OT security truths
Benjamin Bachmann, Director Group Information Security at Bilfinger, speaks with Help Net Security about defending industrial plants. He explains why attackers want to control operations instead of stealing data, and why the air gap is mostly a myth. Bachmann covers how containment plans get negotia...
> Nobody was checking the drives that encrypt your laptop
A drive ships with a label promising hardware encryption. You plug it in, set a password, and trust the chip inside to handle the rest. Millions of laptops and workstations run this way, on solid-state drives built to the TCG Opal2 standard. Milan BroĹľ and three colleagues bought 38 of those drives...