[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> Preparing for Q-day: Four steps to prepare your hybrid cloud today
The arrival of a cryptographically relevant quantum computer, often referred to as Q-day, is moving from a distant theoretical mathematical challenge to an urgent timeline that security teams must plan for today. Bad actors are already engaging in harvest now, decrypt later activities. This means th...
> Zoner
Le fournisseur de services web finlandais Zoner a été victime d'une violation de sécurité sur ses serveurs. L'incident, découvert mardi, a entraîné des problèmes de fonctionnement pour environ 1800 de ses 58000 clients, affectant des sites web et des boîtes e-mail. Des pirates informatiques ont accé...
> PaKK-MED
La PaKK-MED, une association de centres de soins primaires, a été victime d'une attaque par ransomware qui a touché ses systèmes informatiques. L'incident est survenu le 21 juillet 2026. Bien que l'attaque ait entraîné un risque potentiel de fuite de données personnelles (noms, numéros PESEL, donnée...
> Ubuntu 8573-1 Libde265 Critical Denial of Service Vulnerabilities
Several security issues were fixed in libde265.
> Bain thermal de Bad Staffelstein
Un bain thermal populaire à Bad Staffelstein a été ciblé par des hackers.
> Ubuntu 26.04 Wget Important Server-Side Request Forgery Vuln USN-8572-1
Wget could be made to connect to unintended network resources.
> Ubuntu Apache2 Important DoS HTTP Response Issues USN-8571-1
Several security issues were fixed in Apache HTTP Server.
> Estée Lauder discloses data breach via Oracle E-Business flaw
Cosmetics giant Estée Lauder is notifying customers of a data breach after hackers exploited a flaw in Oracle E-Business Suite that the company used for human resources (HR) operations. [...]
> USN-8558-1: ImageMagick vulnerabilities
It was discovered that ImageMagick did not limit mutual references between MVG files. An attacker could possibly use this issue to cause a stack overflow, resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 L...
> 1Password laisse Claude se connecter Ă  vos comptes, sans jamais lui confier vos mots de passe
Avec 1Password for Claude, l'IA se connecte à vos comptes dans le navigateur, sans jamais voir vos mots de passe ni vos codes (MFA). Le post 1Password laisse Claude se connecter à vos comptes, sans jamais lui confier vos mots de passe a été publié sur IT-Connect.
> SonicWall SMA1000 flaws exploited as zero-days to push custom malware
Two recently disclosed SonicWall SMA1000 vulnerabilities were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances. [...]
> Hackers steal $23.7 million in crypto from Ostium in off-chain attack
The Ostium trading platform announced that an attacker stole $23.75 million from its liquidity provider vault last week, after compromising off-chain infrastructure used to feed prices into the protocol. [...]
> Introducing the Amazon GuardDuty investigation agent: on-demand AI-powered threat assessment
The new Amazon GuardDuty investigation agent (now in public preview) investigates security findings across your Amazon Web Services (AWS) environment, reducing investigation time from hours to minutes. GuardDuty is our managed threat detection service that continuously monitors your AWS accounts and...
> Attackers pummel critical WordPress vuln to create all sorts of mischief
Plus dozens of PoCs in the public domain
> Protect Your Privacy with California's DROP Tool
Are you a California resident? Then we've got exciting news for you: there's a tool just for you that lets you take a single, relatively easy step to protect your privacy.  It's called a DROP request. (That's Delete Request and Opt-out Platform, if you're fancy). This one bit of paperwork lets you t...
> wp2shell Aftermath: The First Critical Unauthenticated WordPress Core RCE in Nearly a Decade
wp2shell is a critical unauthenticated RCE chain in WordPress Core, patched July 17, 2026. See who's affected, the exploitation timeline, and what to do now. The post wp2shell Aftermath: The First Critical Unauthenticated WordPress Core RCE in Nearly a Decade appeared first on Wordfence.
> Ubuntu 26.04 Nginx Severe Denial of Service Regressions USN-8563-2
USN-8563-1 introduced a regression in nginx
> USN-8563-2: nginx regression
USN-8563-1 fixed vulnerabilities in nginx. One of the fixes introduced ABI changes that could cause issues with external modules. This update reverts the fix for CVE-2026-42533 pending further investigation. We apologize for the inconvenience. Original advisory details: It was discovered that ng...
> Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes
Researchers escaped the sandboxes in Cursor, Codex, Gemini CLI and Antigravity by having the AI agent write files that trusted host tools later run. Multiple CVEs, patches, and Google downgrading two Antigravity findings. [...]
> JadePuffer agentic attacks now target AI model data with ransomware
The JadePuffer autonomous AI agent has upgraded with custom malware called EncForge that focuses on encrypting AI assets, such as training datasets, vector databases, and model checkpoints. [...]