[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (5 articles)

|

// AI-powered summary generated at 04:00

> Get Nice Holdings
Get Nice Holdings, une société de services financiers cotée à Hong Kong, a été victime d'une cyberattaque le 19 juillet. L'incident a temporairement affecté ses systèmes de trading électronique et d'autres services, y compris les retraits d'actions. Bien que l'unité de titres ait repris ses opératio...
> CCDR Algarve
La CCDR Algarve a été victime d'une cyberattaque durant le week-end (nuit de samedi à dimanche). Suite à la détection d'un accès externe non autorisé, l'organisation a activé ses protocoles internes. Certains services, notamment les communications et l'accès au courrier électronique institutionnel,...
> Update now: 7-Zip fixes RCE flaw exploitable with malicious archives
7-Zip version 26.02 was released to fix a remote code execution vulnerability that could allow attackers to execute malicious code by convincing users to open specially crafted compressed files. [...]
> IJsstadion Thialf
L'IJsstadion Thialf, un important stade de patinage et lieu d'événements situé à Heerenveen, a récemment été la cible d'une cyberattaque par ransomware. L'attaque a été attribuée au groupe malveillant « The Gentlemen ». Les attaquants ont exigé le paiement d’une rançon en échange de la non-publicati...
> Craneware
La société de technologie de la santé britannique, Craneware, a confirmé avoir été victime d'une cyberattaque ayant entraîné le vol de données de clients et d'employés. Basée à Édimbourg, l'entreprise fournit des logiciels au secteur de la santé américain. Bien qu'un volume important de noms de fich...
> OpenSSL Fixes HollowByte Memory Exhaustion Bug
Okta disclosed HollowByte, an 11-byte OpenSSL flaw that lets remote attackers exhaust server memory and trigger denial-of-service attacks. Okta’s Red Team disclosed a denial-of-service vulnerability in OpenSSL they named HollowByte, and the attack payload is exactly 11 bytes. A remote, unauthenticat...
> WordPress Core "wp2shell" RCE flaws get public exploits, patch now
Public exploits have been released for the critical "wp2shell" remote code execution vulnerabilities affecting WordPress Core, making it imperative that administrators patch their sites immediately. [...]
> Two new high severity WordPress vulnerabilities, patch immediately!
The 7.0.2 WordPress security release addresses one critical and one high severity security issue. The vulnerabilities reported to the WordPress security team include: CVE-2026-60137 – A facilitated SQL injection issue reported as a team by TF1T, dtro, and haongo CVE-2026-60137 – A REST API batch-rou...
> Microsoft warns of surge in ACR Stealer attacks on customers
Microsoft has observed a surge in attacks using the ACR Stealer malware to steal browser-stored passwords, authentication tokens, and sensitive documents from its enterprise customers. [...]
> Daxin: 13-Year-Old China-Linked Malware Found Still Active on Manufacturer’s Network
Researchers found China’s Daxin rootkit and a new Stupig backdoor on a Taiwan firm’s network, suggesting a stealthy intrusion dating back to 2013. Symantec’s Threat Hunter Team found Daxin running on a compromised host at a Taiwan-based subsidiary of a multinational high-tech manufacturer in 2026. D...
> The Future of Age Verification: Your Face Never Leaves Your Device
As age verification laws expand worldwide, organizations face growing pressure to protect users' privacy while meeting regulatory requirements. Incode explains how on-device age estimation verifies age without transmitting or storing facial images, reducing biometric privacy risks while supporting c...
> U.S. CISA adds Fortinet FortiSandbox and Microsoft SharePoint flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Fortinet FortiSandbox and Microsoft SharePoint flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Fortinet FortiSandbox and Microsoft SharePoint flaws to its Kn...
> Canicule : les serveurs français sous pression pirate
Seize organisations françaises citées par six groupes pirates entre le 1er et le 16 juillet 2026.
> Cyber actualités de la semaine du 19 juillet 2026
Bonjour à toutes et tous Cette semaine, les fuites de données dominent l’actualité avec NEBBIA, Croqvacances, seize millions de CV exposés et le piratage de l’opérateur Odido. LeakBase voit aussi réapparaître dix téraoctets de données volées.La menace prorusse reste active : NoName057(16) revendique...
> Your Period Tracker Is (Probably) Spying on You
Plus: Russian cyberspies turn to infrastructure hacking, DHS repeatedly fails to realize it’d been hacked, a breach exposes an AI music generator’s scraping ways, and more.
> La base piratée de LFI ressurgit sur un forum pirate
La base volée d’Action populaire ressurgit, exposant militants et organisation aux risques cyber et politiques.
> LeakBase : dix téraoctets piratés réapparaissent
LeakBase fermé, une archive de 10 To de données volées réapparaît via des stockages publics russes.
> Prompt Injection Attacks Are Thwarting AI Hacking Agents
“Context bombing” tricks malicious AI agents into shutting down before they can do harm.
> Un négociateur de rançongiciel condamné à 70 mois
Un négociateur de rançongiciel condamné pour avoir aidé BlackCat à extorquer ses propres clients.
> La piste néerlandaise se précise après le piratage d’Odido
La police explore une piste et une voix après le vol des données de six millions de clients d’un important opérateur téléphonique.