[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (108 articles)

|

// AI-powered summary generated at 16:00

> SonicWall warns of active exploitation of two SMA 1000 zero-days
SonicWall warns of active attacks exploiting two SMA 1000 zero-days, including a flaw enabling arbitrary command execution. SonicWall confirmed the active exploitation of two zero-day vulnerabilities affecting Secure Mobile Access (SMA) 1000 appliances. The vulnerabilities were internally discovered...
> Un hébergeur russe au cœur d’un réseau cybercriminel
Washington accuse la société Media Land d’avoir fourni l’infrastructure ayant soutenu rançongiciels, phishing et fraude.
> CVE-2026-57432 Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack
Information published.
> CVE-2026-39822 Root escape via symlink plus trailing slash in os
Information published.
> Fluke - 821,100 breached accounts
In July 2026, electronic test and measurement equipment company Fluke was targeted in a ShinyHunters "pay or leak" extortion campaign. The group subsequently published more than 100GB of data allegedly taken from the company. The corpus contained largely corporate contact information, including over...
> CVE-2026-42505 Invoking Encrypted Client Hello privacy leak in crypto/tls
Information published.
> USN-8545-1: Linux kernel (HWE) vulnerabilities
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - Block layer subsystem; - Cryptographic API; - DMA engine subsystem; - InfiniBand drive...
> Fortinet adds AI controls and data loss prevention to FortiEndpoint
Fortinet has announced new capabilities for its unified endpoint platform, FortiEndpoint, designed to help organizations securely adopt AI, protect sensitive data, and reduce risk. By bringing AI visibility and control, native data security, endpoint risk scoring, and FortiAI-assisted operations int...
> US charges alleged operators of Russian bulletproof hosting service
U.S. federal prosecutors have unsealed charges against three Russian nationals, accusing them of providing bulletproof hosting (BPH) services to ransomware gangs that caused over $62 million in damages to victims worldwide. [...]
> Product showcase: Trust Chain TPRM turns vendor compliance evidence into verified assurance
Trust Chain is an AI-native third-party risk management (TPRM) solution by Strike Graph that replaces the security questionnaire model with validated evidence of compliance. Rather than asking vendors to self-report their security posture, Trust Chain requires vendors to submit evidence, which is th...
> Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates
Public exploit code targeting the Firefox flaws exists, but no in-the-wild exploitation has been observed. The post Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates appeared first on SecurityWeek.
> Windows 11 KB5101650 : la mise à jour de juillet 2026 est là et elle est bloquée sur certains PC Dell
KB5101650 et KB5099414 : les mises à jour Windows 11 de juillet 2026 sont là. Découvrez les nouveautés et attention au blocage sur certains PC Dell. Le post Windows 11 KB5101650 : la mise à jour de juillet 2026 est là et elle est bloquée sur certains PC Dell a été publié sur IT-Connect.
> Windows 10 KB5099539 : le point sur la mise Ă  jour ESU de juillet 2026
Mardi 14 juillet 2026, Microsoft a publié la KB5099539 pour Windows 10. Correctif OLE Automation, durcissement TDI et RDP : ce que les admins doivent vérifier. Le post Windows 10 KB5099539 : le point sur la mise à jour ESU de juillet 2026 a été publié sur IT-Connect.
> 7 skills and traits of elite security engineers
Security engineers play a pivotal role in enterprise cybersecurity, because they are the professionals who design, build, and deploy security systems to protect an organization’s data, applications, systems, networks, and other IT components against a variety of cyber threats....
> Microsoft dévoile son plus gros Patch Tuesday de l’histoire avec 570 failles et 3 zero-day
Microsoft signe le plus gros lot de correctifs de son histoire, avec trois failles zero-day dont deux exploitées, et au total 570 vulnérabilités patchées. Le post Microsoft dévoile son plus gros Patch Tuesday de l’histoire avec 570 failles et 3 zero-day a été publié sur IT-Connect.
> GDID Windows : impossible Ă  supprimer, mais pas Ă  bloquer
Afficher le GDID de Windows, comprendre pourquoi on ne peut pas le supprimer et bloquer sa transmission à Microsoft : le guide pratique, tests à l'appui. Le post GDID Windows : impossible à supprimer, mais pas à bloquer a été publié sur IT-Connect.
> Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands
SonicWall has warned of active exploitation of two zero-day vulnerabilities impacting Secure Mobile Access (SMA) 1000 series appliances, one of which could be exploited to achieve arbitrary command execution. The vulnerabilities are listed below - CVE-2026-15409 (CVSS score: 10.0) - A Server-si...
> SingGuard-NSFA: Open-source guardrails for agentic AI
SingGuard-NSFA is an open-source guardrail framework aimed at operational threats in agent workflows. Four models ship at 0.8B, 2B, 4B, and 9B parameters, all built on Qwen3.5 base backbones. Risk taxonomy The NSFA risk taxonomy organizes threats along the CIA triad of confidentiality, integrity, an...
> SonicWall Issues Urgent SMA Patch Warning for Two Zero-Day Exploits
SonicWall SMA1000 zero-day vulnerabilities CVE-2026-15409 and CVE-2026-15410 can be exploited for remote code execution. The post SonicWall Issues Urgent SMA Patch Warning for Two Zero-Day Exploits appeared first on SecurityWeek.
> Goose Creek - 6,574,121 breached accounts
In June 2026, a party claiming to have access to data from Goose Creek Candle Company sent emails to a number of the company's customers, claiming the company had a security vulnerability and suffered a data breach. The data was subsequently sent to Have I Been Pwned and contained 6.6M unique email...