> TODAY'S SUMMARY (5 articles)
Today's cybersecurity news highlights several critical issues. OpenAI has acknowledged unauthorized access attempts to four Australian government websites, involving security bypass methods and the use of exposed keys. Citrix has issued patches for actively exploited zero-day vulnerabilities in its NetScaler products, following unofficial warnings that left many users vulnerable. Additionally, Ubuntu is addressing critical regression security issues in curl, which could pose risks to users of version 14.04 LTS. In a positive development, Nvidia launched the Open Agent Safety Platform to enhance governance of agentic AI systems, combining software and hardware for improved monitoring. Overall, the day underscores the ongoing challenges of security vulnerabilities and the need for timely patching.
|
// AI-powered summary generated at 04:00
Le site de la Direction Fiscale de la Mairie de Brașov est indisponible suite à une cyberattaque par malware de type cheval de Troie. Les autorités ont déconnecté temporairement le serveur pour limiter les dégâts et protéger l'infrastructure informatique. Les équipes techniques travaillent à identif...
As a Project Glasswing member, Sophos gains access to Claude Mythos 5, an advanced frontier model not currently available to the public, to find and fix software vulnerabilities before AI-driven attackers can exploit them.
De multiples vulnérabilités ont été découvertes dans Microsoft Edge. Elles permettent à un attaquant de provoquer une atteinte à l'intégrité des données et un problème de sécurité non spécifié par l'éditeur.
De multiples vulnérabilités ont été découvertes dans WordPress. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une injection SQL (SQLi) et un contournement de la politique de sécurité. Le CERT-FR a connaissance d'une preuve de concept publique.
Le 17 juillet 2026, WordPress a publié un correctif pour deux vulnérabilités : CVE-2026-60137 : une injection SQL (SQLi) ; CVE-2026-63030 : celle-ci permet un contournement de la politique de sécurité. Un attaquant peut exploiter ces deux vulnérabilités, de manière combinée, pour obtenir une...
De multiples vulnérabilités ont été découvertes dans Mattermost Server. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.
Ce bulletin d'actualité du CERT-FR revient sur les vulnérabilités significatives de la semaine passée pour souligner leurs criticités. Il ne remplace pas l'analyse de l'ensemble des avis et alertes publiés par le CERT-FR dans le cadre d'une analyse de risques pour prioriser l'application des...
In March 2026, hackers claimed they had obtained data from the gig economy platform Paidwork which they then listed for sale. Almost 11GB of data allegedly obtained from the platform was subsequently posted publicly in July and contained over 23M unique email addresses. The breach also included a br...
F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted HTTP requests. CVE-2026-42533 was patched on July 15 in nginx 1.30.4 (stable) and 1.31.3 (mainline), and in NGINX Plus 37.0.3.1; anyone on an...
A flaw was discovered in tiff, a Tag Image File Format library, which may result in denial of service or the execution of arbitrary code if malformed image files are processed. For the stable distribution (trixie), this problem has been fixed in version 4.7.0-3+deb13u3.
Multiple vulnerabilities were discovered in roundcube, a skinnable AJAX based webmail solution for IMAP servers, which could result in account takeover, cross-site scripting, SSRF bypass, information disclosure or denial of service. For the stable distribution (trixie), these problems have been fixe...
Connect all the things and watch what happens
We have been following issues with Hikvision cameras for a long, long time. Like many similar products, Hikvision cameras have a long history of vulnerabilities and are often targeted by internet-wide scans that our honeypot network detects.
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter CrashStealer: C++ macOS infostealer posing as crash reporter Lucide Proxy: Turning Student Web Proxies into DDoS Bots     AsyncAPI npm organizati...
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. OpenSSL Fixes HollowByte Memory Exhaustion Bug Da...
An advanced threat actor is abusing the update mechanism for the ViPNet private networking product suite to target Russian organizations, including government agencies. [...]
Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting their own machines with data-stealing malware.
According to the Computer Emergency Response Team of Ukraine (CERT-UA), the activity has been attributed to UAC...
A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days prior their public disclosure since June 22, 2026.
Cybersecurity company Volexity is tracking the activity under the moni...
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Two new high severity WordPress vulnerabilities, patch immediately! The 7.0.2 WordPress security release addresses one critical and one high severity security issue. Cynative: Open-source deep research...
Public exploits are now available for two critical WordPress flaws that attackers can chain to gain remote code execution without authentication. Public proof-of-concept exploits are now available for the critical wp2shell vulnerabilities affecting WordPress Core. The flaws, tracked as CVE-2026-6303...