[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (22 articles)

|

// AI-powered summary generated at 08:01

> Chromium: CVE-2026-14394 Use after free in V8
This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
> U.S. CISA adds iCagenda and Balbooa Forms flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds iCagenda and Balbooa Forms flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added iCagenda and Balbooa Forms flaws to its Known Exploited Vulnerabilities (KEV) cata...
> Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install
The jscrambler npm package was compromised, and simply installing its 8.14.0 release runs an infostealer on your machine. Published on July 11, 2026, the malicious version carries a preinstall hook that drops and executes a native binary, one build each for Windows, macOS, and Linux. Socket flagged...
> Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns
Cybersecurity researchers have disclosed details of sustained cyber espionage activity against several Pakistani law enforcement organizations undertaken by suspected China- and India-aligned threat actors between February 2024 and April 2026. "At Balochistan Police, the compromised assets included...
> Critical U-Boot Bugs Undermine Secure Boot on Millions of Devices
Binarly found six U-Boot flaws, including two that enable code execution during boot image verification, impacting 50+ releases. Binarly’s research team has found six vulnerabilities in U-Boot, the open-source bootloader that runs on home routers, smart cameras, server management controllers, and a...
> Ghost Accounts Abuse GitHub API in Mass Recon Campaign
Multiple campaigns are using ghost accounts to map GitHub organizations, including their repositories and members. The post Ghost Accounts Abuse GitHub API in Mass Recon Campaign appeared first on SecurityWeek.
> Doctolib réutilisera des données de santé pour l’IA
Doctolib prépare une recherche médicale avec l’IA : données utilisées, garanties annoncées et procédure de refus.
> Australia warns of global campaign targeting vulnerable CMS platforms
The Australian Cyber Security Centre (ACSC) issued an alert about a global exploitation campaign targeting vulnerable content management systems (CMS) and plugins. [...]
> CVE-2026-58281 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
> Cyber actualités ZATAZ de la semaine du 6 au 12 juillet 2026
Cette semaine, ZATAZ revient sur plusieurs fuites massives, des marchés clandestins d’identités, ainsi que sur des affaires judiciaires liées au dark web.
> IDhack.site, vitrine du contournement des procédures de vérification de l’identité des clients
Des comptes vérifiés vendus avec mail, téléphone et documents révèlent un marché du contournement KYC. ZATAZ vous explique ce blackmarket caché dans le darkweb.
> Glendale Community College - 793,925 breached accounts
In June 2026, Glendale Community College was the target of a ShinyHunters "pay or leak" extortion campaign. Data allegedly obtained from Glendale was later published online and included almost 800k unique email addresses along with various other data fields, including names, addresses, phone numbers...
> Le pixel invisible qui surveille vos e-mails
Un carré blanc d’un pixel suffit à suivre vos lectures. Face à cette collecte discrète, la CNIL impose à présent des règles plus strictes. ZATAZ vous montre comment vous protéger des pixels blancs.
> Découverte d’un faux ongle vendu comme traceur GPS
Sous un vernis rouge se cache une promesse spectaculaire : suivre quelqu’un en temps réel grâce à une puce minuscule, presque invisible, présentée comme un traceur GPS.
> AI Found a Root Bug in Linux That Everyone Missed for 15 Years
Plus: The Pentagon is training amateurs to become part of its hacker army, a Flock license plate reader error led to cops surrounding a car reviewer, and more.
> ToolPie : comparer deux visages pour une enquĂŞte OSINT ?
Deux photos, un doute : ToolPie mesure gratuitement leur ressemblance et aide à vérifier une identité, sans lancer de recherche sur Internet.
> Wireshark 4.6.7 Released, (Sat, Jul 11th)
Wireshark release 4.6.7 fixes 12 vulnerabilities and 16 bugs.
> 'Ghostcommit' hides prompt injection in images to fool AI agents, steal secrets
A PNG hiding a prompt injection could steal your repo's secrets, researchers demonstrate. The technique, dubbed 'Ghostcommit,' slipped past AI code reviewers CodeRabbit and Bugbot, which never open image files at all, then convinced a coding agent to read a repo's .env and write every secret into th...
> CVE-2026-54908 Pion DTLS: Denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message
Information published.
> CVE-2026-56000 xorg-x11-server / xwayland GLX contextTags Use-After-Free in CommonMakeCurrent()
Information published.