[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> The Hidden Privilege of Automation Platforms
Automation platforms such as n8n are often introduced as productivity tools: connect a few systems, automate repetitive work, maybe add some AI. Inside a corporate network, however, that framing is incomplete. A self-hosted workflow engine can reach internal systems, execute actions on behalf of use...
> Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution
Threat actors are now exploiting a recently disclosed critical security flaw impacting ServiceNow AI Platform, according to Defused Cyber. In a post shared on X, the threat intelligence firm said it's observing in-the-wild exploitation of CVE-2026-6875 (CVSS score: 9.5), a sandbox escape vulnerabil...
> ESET Protect On-Prem version 13.1 has been released
ESET Protect On-Prem version 13.1.10.0 has been released.
> Attackers Exploit Critical ServiceNow RCE Flaw CVE-2026-6875
Attackers are exploiting critical ServiceNow flaw CVE-2026-6875, allowing unauthenticated remote code execution on self-hosted instances. Searchlight Cyber researchers disclosed a critical pre-authentication remote code execution vulnerability, tracked as CVE-2026-6875, in the ServiceNow AI Platform...
> The air gap is a myth and other OT security truths
Benjamin Bachmann, Director Group Information Security at Bilfinger, speaks with Help Net Security about defending industrial plants. He explains why attackers want to control operations instead of stealing data, and why the air gap is mostly a myth. Bachmann covers how containment plans get negotia...
> Nobody was checking the drives that encrypt your laptop
A drive ships with a label promising hardware encryption. You plug it in, set a password, and trust the chip inside to handle the rest. Millions of laptops and workstations run this way, on solid-state drives built to the TCG Opal2 standard. Milan BroĹľ and three colleagues bought 38 of those drives...
> Hugging Bay : le « Pirate Bay » des modèles IA ?
Hugging Bay diffuse des modèles IA open source via torrents et miroirs, tout en reprenant le design du célèbre site The Pirate Bay. Qu'en est-il réellement ? Le post Hugging Bay : le « Pirate Bay » des modèles IA ? a été publié sur IT-Connect.
> Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
> ZDI-26-446: Microsoft Windows WMI Providers Incorrect Authorization Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.0. The follow...
> ZDI-26-445: Microsoft Windows WMI Providers Incorrect Authorization Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.0. The follow...
> PR3TACK preemptive framework maps threats before attackers use them
Defensive frameworks in cybersecurity record what attackers have already done. Analysts study a breach, document the method, and build detections around confirmed activity. This cycle leaves a gap between the moment an attacker invents a technique and the moment defenders learn to catch it. PR3TACK,...
> AI agents are still logging in as humans
Most large companies run more than one AI platform at the same time. Developers pull up coding assistants, marketing teams lean on writing tools, and analysts query enterprise search across separate vendors. Single-provider setups keep giving way to mixed stacks as companies keep their options open....
> OVH reveals semi-secret plan to fix critical Januscape bug with mass reboots – and an Australian crash-test dummy
French cloud backported a patch into Debian and didn’t seek customer consent, despite chance of downtime
> Cybersecurity jobs available right now: July 21, 2026
Application Security Analyst Stellantis | USA | On-site – View job details As an Application Security Analyst, you will perform application security testing using SAST, DAST, IAST, and other assessment tools to identify vulnerabilities and support remediation efforts. You will integrate security con...
> AI-generated reports push GNOME to shorten its disclosure window
Volunteer maintainers of open source projects now receive a steady flow of security vulnerability reports produced with AI tools. Many arrive with no mention that a language model helped write them. The volume has grown enough that GNOME is revising the rules it uses to track and disclose vulnerabil...
> ISC Stormcast For Tuesday, July 21st, 2026 https://isc.sans.edu/podcastdetail/10016, (Tue, Jul 21st)
> Multiples vulnérabilités dans Tenable Security Center (21 juillet 2026)
De multiples vulnérabilités ont été découvertes dans Tenable Security Center. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une injection SQL (SQLi) et un contournement de la politique de sécurité.
> Asamblea Legislativa
La présidente de l'Assemblée législative a confirmé que le Congrès avait été victime d'une cyberattaque qui avait compromis ses systèmes informatiques. Cette annonce a été faite lors d'une séance plénière, après qu'une députée eut fait part de son inquiétude concernant la panne du site web instituti...
> Sophos Named a Leader in the IDC MarketScape for Worldwide Managed Detection and Response Services for Midmarket 2026
Sophos has been named a Leader in the IDC MarketScape for Worldwide Managed Detection and Response Services for Midmarket 2026, recognizing our intelligence-led MDR, flexible engagement models, and open platform approach.
> July Patch Tuesday only feels endless
AI deluge brings 575 CVEs, 479 advisories, reset to blog-post format