[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (21 articles)

|

// AI-powered summary generated at 20:00

> UODO - autorité polonaise
L'autorité polonaise de protection des données (UODO) a détaillé les implications de la Loi sur la cyber-résilience (CRA), le Règlement (UE) 2024/2847, et ses interactions avec le RGPD.L'article 14 de ce règlement sera applicable dès le 11 septembre 2026 et concernera les produits avec des éléments...
> ICO - autorité britannique
Le Bureau du Commissaire à l'information (ICO) a annoncé l'ouverture d'une enquête sur la conformité de la Police d'Écosse concernant le traitement des demandes d'accès aux données.L'enquête vise à déterminer si la Police d'Écosse a manqué à ses obligations légales en vertu des articles 12 et 15 du...
> Update your firewall rules: Teams and Copilot are changing address
Microsoft is changing the destination address of two of its most popular services: starting this month, it will redirect M365 and Teams web users to copilot.cloud.microsoft and teams.cloud.microsoft, respectively. The Teams move is already under way, and Microsoft has now a...
> AEPD - autorité espagnole
L'autorité espagnole de protection des données a sanctionné la Direction Générale de la Police pour des manquements graves concernant le traitement de données biométriques aux contrôles frontaliers, notamment une information insuffisante des voyageurs et l'absence d'une analyse d'impact conforme.Fai...
> GPDP - autorité italienne
L'autorité italienne de protection des données (GPDP) a publié une décision de sanction à l'encontre de l'Entreprise Spéciale pour la Gestion des Installations Sportives de la Commune de Trente (A.S.I.S.) pour des manquements en lien avec l'installation de caméras de vidéosurveillance dans les vesti...
> Cold TAKE: Amazon's New Encryption Method Still Doesn't Deliver Real Privacy
Amazon recently debuted a new feature for its Ring cameras that the company is calling Throw Away the Key Encryption (TAKE). The idea is to cut back on the amount of video content available to the company, and thus potentially available to law enforcement. But while it might technically add a speed...
> AEPD - autorité espagnole
Une attaque par rançongiciel chez un sous-traitant a conduit l'autorité espagnole à sanctionner le responsable de traitement, VODAFONE, à hauteur de 500 000 €, en retenant sa responsabilité pour des défaillances de sécurité structurelles sur sa propre infrastructure, notamment l'absence d'authentifi...
> AEPD - autorité espagnole
Une décision sanctionnant un responsable pour l'absence de contrat de sous-traitance en vigueur au moment d'une violation de données, l'autorité ayant rejeté la validité d'un accord signé rétroactivement, ainsi que pour des mesures de sécurité jugées insuffisantes chez le sous-traitant.Faits et cont...
> GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure
GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure. The vulnerability in question is CVE-2026-85706 (CVSS score: 10.0), a path traversal issue in the repository commits AP...
> PIPC - autorité sud-coréenne
La Commission de protection des informations personnelles (PIPC) sud-coréenne a initié une enquête sur Google concernant une potentielle fuite de données de victimes de crimes sexuels numériques.L'enquête fait suite à des rapports médiatiques indiquant que des demandes de suppression de contenus, so...
> Artifactory flaws chained in attacks deploying backdoor malware
Threat actors are exploiting critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication, gain administrative privileges, and deploy a Rust backdoor on vulnerable self-hosted servers. [...]
> ConnectWise patches critical ScreenConnect authentication failure after five days
ConnectWise has issued a security update for ScreenConnect, five days after warning customers the product could allow files to be transferred and executed through active remote sessions without authorization or confirmation. The company warned customers on Sept. 3 of the pr...
> Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks
Anthropic on Thursday said it identified and disrupted industrial-scale illicit distillation attacks against Claude from seven labs based in China, including Alibaba, Moonshot, DeepSeek, Z.ai (aka Zhipu), and MiniMax. Knowledge distillation by itself is a legitimate training method. It refers to a...
> GitLab Vulnerability Exploited One Day After Disclosure
The critical-severity path traversal flaw allows unauthenticated attackers to read arbitrary files from the GitLab server. The post GitLab Vulnerability Exploited One Day After Disclosure appeared first on SecurityWeek.
> India’s STPI serves TerminalFix-style attack via fake Cloudflare check
A website linked to India’s Software Technology Parks of India (STPI) is serving a spoofed Cloudflare verification page that silently copies a malicious string to visitors’ clipboards and prompts them to execute it via Windows Terminal, in a technique consistent with emerging...
> Crypto customers targeted by scammers after email marketing provider breach
A breach at email marketing company Brevo exposed Trezor, CoinTracking, and BitBox customers to phishing emails, but others may also be at risk.
> The Self-Expanding Stolen Inference Supply Chain: An AI Agent Harvesting and Re-Serving LLM Access, (Fri, Sep 11th)
I identified an attacker using a semi-autonomous coding agent to run an offensive operation: finding poorly secured LLM resale gateways, acquiring API access through ordinary web flaws and account farming, validating the resulting inference capacity, and aggregating it behind a single gateway of the...
> Microsoft Teams : une fonction de sauvegarde et de restauration des équipes et des canaux arrive en décembre
Microsoft prépare une fonction native de sauvegarde et de restauration des équipes et canaux Teams, avec une disponibilité prévue en décembre 2026. Le post Microsoft Teams : une fonction de sauvegarde et de restauration des équipes et des canaux arrive en décembre a été publié sur IT-Connect.
> Claude Used to Automate Exploitation and Data Theft Across Multiple Victims
Anthropic has warned that cybercriminals and state-sponsored hackers alike are using its Claude models for cyber attacks, weapons design, propaganda, and mass surveillance between December 2025 and August 2026. The threat actors, which the artificial intelligence (AI) company has branded Generative...
> In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review
Noteworthy stories that might have slipped under the radar: Invisible Unicode slips past phishing filters, US puts $10 million bounty on Iranian cyber official, military ties of Chinese hacking group QTFY. The post In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review ap...