[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (135 articles)

|

// AI-powered summary generated at 20:00

> “Stern,” Likely Most Prolific Ransomware Operator Ever, Sanctioned by EU as Action Targets Billions in Ransomware Damage
Summary The United States, United Kingdom, and European Union announced sanctions targeting nation-state hackers, cybercriminals, and their enablers in one… The post “Stern,” Likely Most Prolific Ransomware Operator Ever, Sanctioned by EU as Action Targets Billions in Ransomware Damage appeared firs...
> Authenticate legitimate AI agent traffic with AWS WAF Bot Control
As AI agents and automated tools increasingly access web applications, distinguishing legitimate bot traffic from malicious attempts has become a critical security challenge. Traditional approaches such as IP-based filtering and reverse DNS lookups fail in multi-tenant systems (such as Amazon Bedroc...
> USN-8539-1: GnuTLS vulnerabilities
Haruto Kimura discovered that GnuTLS did not properly apply permitted name constraints in certain certificate validation paths. A remote attacker could possibly use this issue to bypass certificate validation, leading to a machine-in-the-middle attack. (CVE-2026-42011) Oleh Konko discovered that Gn...
> Iran abused mobile networks’ vulnerabilities to locate US military in the Middle East, report says
The Iranian government exploited well-known flaws in cellphone networks to locate and then strike U.S. military personnel in the build-up and beginning of the war.
> The End Of Manual Transcription Starts Here
Spend less time manually reviewing audio and video evidence with S21 Transcriber v2.0 – an offline, rapid and accurate way to turn spoken material into searchable, structured intelligence.
> Telegram’s shortlink domain is back online after day-long suspension
Telegram CEO Pavel Durov confirmed an outage in a tweet, saying that shortlinks to the messaging app had "stopped working."
> CVE-2026-49797 Windows NTFS Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
> CVE-2026-50427 Content Delivery Manager Elevation of Privilege Vulnerability
Use after free in Content Delivery Manager allows an authorized attacker to elevate privileges locally.
> CVE-2026-49798 Windows Kernel Elevation of Privilege Vulnerability
Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.
> CVE-2026-50299 Windows Storage Spaces Direct Remote Code Execution Vulnerability
Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to execute code with a physical attack.
> CVE-2026-49800 Windows Web Proxy Auto-Discovery Protocol (WPAD) Elevation of Privilege Vulnerability
Integer overflow or wraparound in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authorized attacker to elevate privileges locally.
> CVE-2026-49799 Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability
Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network.
> CVE-2026-50308 Windows NTFS Remote Code Execution Vulnerability
Integer underflow (wrap or wraparound) in Windows NTFS allows an unauthorized attacker to execute code locally.
> CVE-2026-50311 Windows Server Elevation of Privilege Vulnerability
Improper access control in Windows Server allows an authorized attacker to elevate privileges locally.
> CVE-2026-49804 Windows USB Video Driver Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows USB Video Driver allows an unauthorized attacker to elevate privileges with a physical attack.
> CVE-2026-50294 Windows Kernel Information Disclosure Vulnerability
Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an unauthorized attacker to disclose information locally.
> CVE-2026-50333 Windows Spaceport.sys Elevation of Privilege Vulnerability
Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.
> CVE-2026-49801 Windows SMB Information Disclosure Vulnerability
Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.
> CVE-2026-49802 Windows USB Print Driver Elevation of Privilege Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.
> CVE-2026-49806 Windows USB Print Driver Elevation of Privilege Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.