[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (22 articles)

|

// AI-powered summary generated at 08:01

> Organizations Warned of Exploited Joomla Extension Vulnerabilities
Threat actors have been targeting Balbooa Forms and iCagenda Joomla extension flaws for remote code execution. The post Organizations Warned of Exploited Joomla Extension Vulnerabilities appeared first on SecurityWeek.
> Claude Code users keep 50% higher limits until July 19
Anthropic has extended a limited-time promotion that increases weekly usage limits in Claude Code by 50% through July 19, 2026, at 11:59 PM PT. When the promotion ends, weekly usage limits will return to their standard levels without any changes to users’ plans or billing. The promotion is available...
> Your AI risk register is not an incident response plan
Picture the moment after an AI issue is reported. A security analyst is reviewing a ticket reporting that an internal AI tool produced the wrong recommendation in a live business workflow. The risk is not theoretical anymore. Someone wants to know whether this is a security...
> AI-generated code has made security debt a governance problem
Moving from tool approval to true governance is the only way for CISOs to keep pace with the accelerating velocity of software risk. The post AI-generated code has made security debt a governance problem appeared first on CyberScoop.
> Australian Cyber Agency Warns of Global CMS Exploitation Campaign
Australian Cyber Security Centre warns CMS users of mass scanning and exploitation campaign
> Progress Prompts ShareFile Storage Zone Controller Shutdown Amid Security Concerns
The company notified customers to manually shut down their servers while it is investigating a credible threat. The post Progress Prompts ShareFile Storage Zone Controller Shutdown Amid Security Concerns appeared first on SecurityWeek.
> Centers Laboratory Data Breach Affects 540,000 Individuals
The WorldLeaks extortion group claimed to have stolen 720 GB of data from the healthcare testing and laboratory services provider. The post Centers Laboratory Data Breach Affects 540,000 Individuals appeared first on SecurityWeek.
> Australia Alerts Organizations to Ongoing CMS Exploitation Attacks
Australia warns of a global campaign exploiting CMS flaws to deploy webshells on WordPress, Joomla, and other websites. Australia’s Signals Directorate has issued an alert about a large-scale exploitation campaign actively targeting content management systems (CMS) worldwide, with many small and med...
> Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365
An attacker running a live Microsoft 365 phishing operation left a Python web server listening on a public port with directory listing switched on. The command that did it: python3 -m http.server 8080, was still sitting in the readable .bash_history. From that one lapse, French security firm Lexfo ...
> Windows 11 : ce composant lié à Mobile Connecté engloutit la RAM de votre PC
Des utilisateurs de Windows 11 rapportent que Cross Device Service, lié à Mobile Connecté, sature la RAM (parfois plus de 30 Go). Microsoft n'a rien confirmé. Le post Windows 11 : ce composant lié à Mobile Connecté engloutit la RAM de votre PC a été publié sur IT-Connect.
> A week in security (July 6 – July 12)
A list of topics we covered in the week of July 6 to July 12 of 2026
> Can AI narrow cybersecurity’s class divide?
At Amazon Web Services (AWS), artificial intelligence is already compressing security work that once took months into minutes. In the old world, human red teams would find vulnerabilities, write reports, refine those reports, and eventually hand them to defenders, who would...
> Debian 13.6 est disponible : découvrez les changements principaux
Debian 13.6 apporte une série de correctifs de sécurité et met à jour fwupd pour accompagner l'expiration du certificat UEFI Secure Boot. Ce qu'il faut savoir. Le post Debian 13.6 est disponible : découvrez les changements principaux a été publié sur IT-Connect.
> Gestionnaire de mots de passe en entreprise : pourquoi et comment franchir le pas
Excel, post-it, e-mails : structurez enfin vos accès. Risques, critères de choix et bonnes pratiques du gestionnaire de mots de passe en entreprise. Le post Gestionnaire de mots de passe en entreprise : pourquoi et comment franchir le pas a été publié sur IT-Connect.
> Why SBOMs, signing, and provenance still don’t tell you if software is safe
We have made real progress in software supply chain security, improving visibility into software components, authenticity and build integrity. Much of this progress traces back to Executive Order 14028, which pushed agencies, contractors and enterprises to invest in SBOMs, signing and provenance. Al...
> Microsoft 365 : rappeler un e-mail envoyé à une autre entreprise, bientôt possible
Microsoft va déployer le rappel d'e-mails inter-tenant sur Exchange Online dès août 2026, via une liste d'autorisation gérée par l'organisation. Le post Microsoft 365 : rappeler un e-mail envoyé à une autre entreprise, bientôt possible a été publié sur IT-Connect.
> Cynative: Open-source deep research agent
Running a large language model against a live cloud account to hunt for security holes comes with an obvious hazard. An agent that holds real credentials and a mandate to poke around can delete a bucket, flip a permission, or leak a secret on its way to a finding. Cynative, an open-source security r...
> iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two maximum-severity security flaws impacting iCagenda and Balbooa extensions for Joomla to its Known Exploited Vulnerabilities (KEV) catalog, following reports of zero-day exploitation in the wild. The vulnerabilities, both...
> Microsoft demystifies how Windows updates work
Microsoft has published a guide explaining the Windows servicing model, outlining the purpose of monthly security updates, optional preview releases, hotpatch updates, and the mechanisms used to deliver new features throughout the year. “Most individuals and organizations regularly deploy monthly se...
> Muse Image : comment empêcher Meta de piocher dans vos photos Instagram ?
Meta a lancé Muse Image, un générateur IA capable de puiser dans les photos des comptes Instagram. Voici comment désactiver cette réutilisation par défaut. Le post Muse Image : comment empêcher Meta de piocher dans vos photos Instagram ? a été publié sur IT-Connect.