[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (54 articles)

|

// AI-powered summary generated at 12:00

> LegacyHive : la zero-day Windows publiée juste après le Patch Tuesday de juillet
Nightmare Eclipse a publié LegacyHive, une zero-day dans le service de profils utilisateur de Windows. Elle fonctionne sur les machines Windows et WS à jour. Le post LegacyHive : la zero-day Windows publiée juste après le Patch Tuesday de juillet a été publié sur IT-Connect.
> Most Smart Watches, Rings, and Bands Lack Basic Transparency Reports and Key Privacy Features
Oura Rings, Garmin GPS fitness watches, Apple Watches, Whoop bands—every year, more and more tech devices are promising to monitor our health and fitness, guide us toward healthier living, and provide useful health metrics to take to our doctors. But few of these tools provide the sorts of privacy a...
> Key vulnerabilities of Microsoft’s July 2026 Patch Tuesday
Which Windows, SharePoint, and AD vulnerabilities are being exploited in July 2026, and how can organizations adapt to updates containing 500+ fixes?
> US and allied Governments’ Recommendations: Securing Network Devices Against Russian APT Groups
US and allies warn of Russian APT groups targeting routers and network devices to compromise critical infrastructure worldwide. The US and allied governments warn that Russian state-sponsored APT groups are scanning and exploiting poorly secured network devices, especially routers, to access critica...
> SonicWall customers under threat as attackers exploit 2 zero-days
Researchers said the vulnerabilities, which attackers are chaining together, were first exploited three weeks before the vendor disclosed and patched the defects. The post SonicWall customers under threat as attackers exploit 2 zero-days appeared first on CyberScoop.
> California Steps Back From Dangerous Expansion of its Age-Gating Law
The California legislature has stepped back from a plan that would have expanded its age-gating law, removing language that could have compounded serious threats to users’ speech, privacy and security just to browse the internet. A.B. 1856, authored by Assemblymember Buffy Wicks, will now move forwa...
> Microsoft patches bug in video game Age of Empires II
The vulnerability in the decades-old game could have allowed hackers to take over victims’ computers with a malicious game invite.
> TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development
Cybersecurity researchers have disclosed details of a previously unreported Internet-of-Things (IoT) botnet framework dubbed TuxBot v3 Evolution that shows signs of being developed with assistance from a large language model (LLM), albeit with not so successful results. "While the AI complied with...
> Google Gemini CLI abused as a hacking agent, malware botnet operator
A Russian-speaking threat actor known as "bandcampro" used Google's open-source Gemini CLI AI tool as a hacking agent and to operate a small-scale botnet. [...]
> Dems press DNI nominee Jay Clayton on election security questions, but leave dismayed
Clayton maintained he was not an “election denier” but wouldn’t directly answer a number of questions about the 2020 race, his predecessor’s appearance at a January election office raid and more. The post Dems press DNI nominee Jay Clayton on election security questions, but leave dismayed appeared...
> How to conduct a password audit for your business
Learn how to conduct a password audit with a step-by-step framework to identify weak passwords, risky access, and poor credential hygiene.
> Trump’s DNI pick grilled about election security, voter fraud
Senators pressed director of national intelligence nominee Jay Clayton about his stance on the 2020 election and previous statements about voter fraud. Other issues took a back seat.
> 23andMe reaches $18 million settlement with states for massive breach
A coalition of 42 state attorneys general reached an $18 million settlement with 23andMe for cybersecurity failings that led to a data breach.
> USN-8553-1: .NET vulnerabilities
Artur Stetsko discovered that the .NET did not properly validate authentication data. An attacker could possibly use this issue to elevate privileges. (CVE-2026-47300) Levi Broderick discovered that .NET did not properly handle XML encryption during parsing. An attacker could possibly use this issu...
> đźš« Don't Let Congress Age-Gate the Internet | EFFector 38.13
The effort to age gate the internet is back in Washington—and now it has a new name. Recently passed by the House of Representatives, the KIDS Act is a sprawling package of proposals to control what we can see and say online. Supporters claim the KIDS Act is needed to protect minors online. But if l...
> Hack suggests AI music generator Suno scraped YouTube for training data
The hacker used an employee's credentials to access source code, which revealed how Suno scraped decades of audio.
> Ubuntu 24.04 Sympa Important Path Traversal Vuln 2024-55919
Sympa could allow unintended access to network services.
> Chaotic Eclipse Unveils LegacyHive Exploit Affecting Fully Patched Windows Systems
LegacyHive PoC exposes a Windows Privilege Escalation flaw affecting fully patched Windows desktop and server systems. Just hours after Microsoft’s July 2026 Patch Tuesday, security researcher Nightmare Eclipse, also known as Chaotic Eclipse, published a new Windows zero-day proof-of-concept called...
> Ubuntu Tomcat Important Security Flaws CVE-2026-43515 CVE-2026-50229
Several security issues were fixed in Tomcat.
> APD - autorité belge
La Chambre des représentants a désigné le nouveau directeur de la Chambre Contentieuse de l'Autorité de protection des données (APD), complétant ainsi le comité de direction de l'autorité.Le nouveau directeur, un magistrat, a prêté serment le 15 juillet 2026, succédant à son prédécesseur qui a quitt...