[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (54 articles)

|

// AI-powered summary generated at 12:00

> USN-8551-1: Tomcat vulnerabilities
It was discovered that Tomcat incorrectly handled authorization when multiple method constraints defined the same HTTP method. A remote attacker could possibly use this issue to bypass authorization restrictions. (CVE-2026-43515) It was discovered that the Tomcat number guess example application di...
> Dutch police dismantle global crypto investment scam, arrest alleged mastermind
Authorities said Wednesday that the group operated like a legitimate international business since at least 2021, running about two dozen call centers across several countries and employing more than 700 people who posed as professional financial advisers.
> CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities
Three vulnerabilities are actively exploited in attacks, including two that have been targeted as zero-days. The post CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities appeared first on SecurityWeek.
> We built a vulnerability vending machine: AI tokens in, zero-days out
Intruder built an AI-powered "vulnerability vending machine" that combines code slicing with LLMs to automatically discover complex software vulnerabilities. The company explains how the system found and exploited a previously unknown WordPress plugin zero-day, with additional discoveries already un...
> Eleven Vulnerable UEFI Shims Enable Secure Boot Bypass
Eleven forgotten Microsoft-signed UEFI shims can bypass Secure Boot on almost any machine
> USN-8550-1: libslirp vulnerability
It was discovered that libslirp incorrectly handled TCP urgent data. A privileged attacker inside a guest VM could possibly use this issue to obtain sensitive information from the host process memory.
> Threat actor impersonated hundreds of brands on GitHub to push infostealer malware
A financially motivated threat actor is impersonating hundreds of brands on GitHub and pushing a smash-and-grab infostealer masquerading as legitimate downloads of popular software, Arctic Wolf threat researchers have warned. “The 292 impersonated repositories span security tooling, fintech and pers...
> Socure rolls out Remote Verifier for higher-risk identity checks
Socure has launched Remote Verifier in RiskOS, a new identity verification tool that helps organizations verify identities requiring additional review while reducing manual effort. Socure’s AI-powered document verification solution instantly verifies more than 99% of identities on the first try, com...
> USN-8549-1: idna vulnerability
It was discovered that idna did not properly reject oversized inputs before performing expensive processing. An attacker could possibly use this issue to cause idna to consume significant resources, leading to a denial of service.
> Xint Pulse offers on-demand black-box penetration testing for web applications
Xint.io has launched Xint Pulse, a black-box autonomous penetration testing tool that provides product security teams with on-demand security assessments of their applications. Unlike the company’s enterprise platform, which is designed for continuous testing, Xint Pulse is intended for timely, one-...
> Microsoft cancels Patch Tuesday for some Dell users over surprise shutdowns, overheating devices
Mega hardware vendor reports problems - but Windows maker isn't yet naming affected models
> Oracle Linux 9 ELSA-2026-39316 Cups Moderate Control Character Injection
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
> Oracle Linux 9 Git-LFS Important Update ELSA-2026-39319 CVE-2026-33811
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
> F5 Insight for ADSP enhances BIG-IP operations with guided updates and AI audit trails
F5 has announced new fleet management capabilities for F5 Insight for ADSP that help enterprises reduce risk exposure across F5 BIG-IP environments as frontier AI compresses vulnerability response timelines. The new F5 Insight workflows give security and operations teams fleet-wide visibility, guide...
> Oracle Linux 9 libxml2 Low CVE-2025-6170 Advisory ELSA-2026-39317
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
> Oracle Linux 9 libsolv Moderate Buffer Overflow Advisory ELSA-2026-39315
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
> Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws
Mozilla has released updates to address two critical flaws in Firefox for which it warned that exploit code has been published. The vulnerabilities are listed below - CVE-2026-15718, an invalid pointer in the JavaScript: WebAssembly component CVE-2026-15719, a site isolation in the DOM: Navig...
> Oracle Linux 9 qemu-kvm Low Heap Overflow Fix ELSA-2026-39311
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
> New Windows Bind Link techniques let attackers evade EDR, security controls
Attackers who already have administrator privileges on a Windows machine have newer ways to slip past endpoint security without exploiting a vulnerable driver or modifying trusted binaries. Bitdefender researchers have warned against three techniques that abuse Windows Bind...
> Windows Bind Link Attacks Can Hide Malware From EDR Tools
Bitdefender researchers show how Windows bind links can create conflicting filesystem views to hide malware from endpoint security products. The post Windows Bind Link Attacks Can Hide Malware From EDR Tools appeared first on SecurityWeek.