[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (21 articles)

|

// AI-powered summary generated at 20:00

> Why AI raises the stakes for exposure validation
AI dominated the conversation at Fal.Con 2026, but one of the most important takeaways wasn’t simply how AI is changing cyber defense. It was how AI is changing the speed and scale of a problem defenders already face. Security teams already have more vulnerabilities and sec...
> Cyberattack causes a flight delay? Airlines won’t owe you a hotel or meal
A Department of Transportation rule published last week says that airlines complying with cybersecurity regulations will have reduced customer obligations in the event of an attack. The post Cyberattack causes a flight delay? Airlines won’t owe you a hotel or meal appeared first on CyberScoop.
> Friday Squid Blogging: Rotting Squid on a Beached California Boat
Smells awful: But an estimated 30 to 50 tons of dead squid remain inside the boat’s catch tank, where they have been decomposing for days. “That is nasty. I wouldn’t want to do that,” said commercial fisherman Dick Ogg of the Bodega Bay Fishermen’s Marketing Association. Ogg said anyone familiar wi...
> Debian Trixie SPIP Important Remote Code Execution DSA-6495-1
Several vulnerabilities were discovered in SPIP, a website engine for publishing, which could result in unauthenticated remote code execution. For the stable distribution (trixie), these problems have been fixed in version 4.4.23+dfsg-0+deb13u1. We recommend that you upgrade your spip packages.
> Weekly Update 521: Breach Perception v. Reality
Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSiteI think what really resonates with me this week is being able to completely turn the tables on perceptions around things like AI being the big bad hacki...
> Debian Kamailio Important Denial of Service Vulns DSA-6494-1
Multiple security vulnerabilities were discovered in the Kamailio SIP server, which could result in denial of service. For the stable distribution (trixie), these problems have been fixed in version 6.0.1-1+deb13u2. We recommend that you upgrade your kamailio packages.
> Governor Newsom Signs Student-Backed Digital Literacy Bills Alongside Misguided Bans
Governor Newsom signed a package of 12 bills yesterday aimed at “protecting children” online. One of them was AB 1709, which EFF has opposed this legislative session and serves as a functional ban on young people under 16 using social media. However, EFF supported two of the bills signed into law, A...
> Hackers abused Claude to extract secrets from 1.8M Android apps
Anthropic says multiple threat groups, including the financially motivated and state-sponsored espionage groups linked to Russia and China, tried to abuse its Claude AI model for malicious purposes. [...]
> Florida says motor vehicle data breach tied to credentials stolen from officer’s personal device
The Florida Department of Motor Vehicles confirmed a data breach claimed by the cybercrime group ShinyHunters, saying it originated with the theft of credentials stored on a police officer's personal device.
> Florida confirms DMV database breached via stolen police account
The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its DAVID driver database suffered a data breach, saying the attackers gained access using credentials belonging to a police department employee. [...]
> Meta Sued Over Training Data for Its AI and Face-Recognition Systems
The proposed class action alleges Meta illegally harvested people’s Facebook and Instagram photos to train its AI image-generation models and to build its unreleased “NameTag” face recognition feature.
> GitLab’s critical flaw is already drawing internet-wide probes
One flaw allows an unauthenticated attacker to read files from the server. GitLab urged operators of self-managed installations to upgrade immediately. The post GitLab’s critical flaw is already drawing internet-wide probes appeared first on CyberScoop.
> Microsoft sees some new wrinkles in invoice-scam emails
Researchers analyzed a flood of fraudulent business emails and found that the threat actors had doubled-up on tactics to make them appear legitimate, including help from AI.
> My Talk at DEF CON
Last month, I gave a talk at DEF CON on AI hacking: what happens when AIs become hackers. It’s a combination of the potentialities I raised in my 2022 book A Hacker’s Mind and the lessons we’re learning from current AI models engaging in hacking behavior. I’m really proud of the talk, and the fact t...
> More JFrog Artifactory bugs under attack, and all 3 have patches
If you're waiting for a sign to upgrade to a fixed version: this is it
> The AI Supply Chain Has a Security Problem, and Much of It Is Sitting on the Open Internet
Researchers found 36,769 exposed AI endpoints, but only 2% had an HTTP authentication gate. Running AI locally is supposed to give organizations more control. Models, prompts and documents stay on infrastructure they manage instead of being sent to a third-party cloud. But that advantage disappears...
> Passkey-themed phishing attacks lead to Microsoft 365 data theft
Microsoft says threat actors linked to ShinyHunters, Helix, and other extortion gangs are using passkey and single sign-on-themed social engineering attacks to compromise corporate Microsoft accounts and steal data from Microsoft 365 services. [...]
> Phishing Research Challenges Conventional Security Awareness Testing
Analysis of 2.47 million simulated attacks shows why organizations should measure credential leaks and reporting, not just clicks. The post Phishing Research Challenges Conventional Security Awareness Testing appeared first on SecurityWeek.
> Médias et blogs
Le Conseil constitutionnel a validé la quasi-totalité de la loi RIPOST, qui étend plusieurs dispositifs de surveillance en France.Adoptée en juin dernier, la loi portée par le ministre de l'intérieur Laurent Nuñez a été examinée par le Conseil constitutionnel, qui a approuvé la majeure partie du tex...
> Personuvernd - autorité islandaise
L'Autorité islandaise de protection des données (Persónuvernd) a initié des enquêtes suite à des plaintes concernant le traitement de données personnelles dans le cadre du référendum du 29 août 2026.L'autorité a reçu 54 signalements et plaintes relatifs à des communications non sollicitées et au tra...