[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> Oracle Linux 8 Kernel Important Security Advisory ELSA-2026-39179
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
> Oracle 8 hplip Important Buffer Overflow Fix ELSA-2026-40894
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
> “Stealth Crawlers” Are Not a Threat to the Open Web. Bills Targeting Them Would Be.
There’s a new boogeyman in the battles over AI: so-called “stealth crawlers.” We’ll admit it—the term “stealth crawlers” sounds quite nefarious. In reality, they’re anything but. “Stealth crawlers” are simply automated tools to access and collect public web data—without disclosing the user’s identit...
> Frontier LLMs couldn't help Hugging Face fight off evil agents
Chinese open-weight model GLM 5.2 happily obliged
> WordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th)
Last week, Searchlight Cyber released details about a vulnerability they are calling "wp2shell". The vulnerability was initially announced without a CVE number. But now has been assigned CVE-2026-63030. Many WordPress plugin vulnerabilities are never assigned CVE numbers. But wp2shell is different....
> FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intelligence (AI) skills or Model Context Protocol (MCP) servers to deliver a malware family known as SmartLoader as part of an ongoing campaign codenamed FakeGit. "Fa...
> India says allegedly leaked nuclear plant files pose no safety risk
Documents that the World Leaks cybercrime group claimed to leak from the Kudankulam Nuclear Power Plant do not contain information pertaining to safety or security, Indian officials said.
> Director of Commerce AI standards office out after three months
The Center for AI Standards and Innovation has quietly become a key hub for the federal government to assess potential threats and harms that AI systems pose. The post Director of Commerce AI standards office out after three months appeared first on CyberScoop.
> Ubuntu 26.04 SQLite Critical DoS Buffer Overread USN-8565-1
Several security issues were fixed in SQLite.
> Ubuntu 26.04 PHP Significant Denial of Service Flaws USN-8564-1
Several security issues were fixed in PHP.
> New HollowGraph malware uses Microsoft Graph for stealthy C2 comms
A malicious component dubbed HollowGraph uses the calendar feature in compromised Microsoft 365 mailboxes as a command-and-control channel to receive attacker commands and exfiltrate stolen data. [...]
> Ubuntu 26.04 nginx Critical Denial of Service Vuln 8563-1
Several security issues were fixed in nginx.
> Ubuntu 26.04 FreeRDP Important Code Execution Vulnern 8561-1
Several security issues were fixed in FreeRDP.
> How to turn off Apple Intelligence on iPhone, iPad, and Mac
Apple's generative AI system is on by default on iOS and macOS. Here's how to turn off Apple Intelligence completely or just unused features.
> Ubuntu 26.04 FreeType Important Denial of Service CVE-2026-50811
FreeType could be made to crash if it opened a specially crafted file.
> Fraude scolaire : le piège des frais de scolarité est de retour
Une fausse facture scolaire de 350 € cible des étudiants avec un virement urgent et une adresse trompeuse.
> Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign
A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments, droppers, builder notes, and two campaign chains. One was already live against Windows users in Mexico, delivering an...
> HOLLOWGRAPH malware turns Microsoft 365 calendars into an espionage channel
Microsoft 365 calendars have become a hiding place for espionage malware, with commands and stolen files stashed inside appointments dated to the year 2050, researchers from Group-IB discovered. Targeted campaign tied to Iranian espionage activity The malware, which Group-IB calls HOLLOWGRAPH, is on...
> Cyber insurance for small businesses: what you need to know before buying
Cyber insurance is valuable but it can’t replace good security. Learn what it covers, including security requirements and costs.
> More than 1,000 domains illegally streaming World Cup games seized, DOJ says
Over the course of the World Cup tournament, the Department of Justice seized more than 1,000 domains for illegally streaming games.