[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (57 articles)

|

// AI-powered summary generated at 12:00

> CVE-2026-56000 xorg-x11-server / xwayland GLX contextTags Use-After-Free in CommonMakeCurrent()
Information published.
> CVE-2026-59869 js-yaml: YAML merge-key chains can force quadratic CPU consumption
Information published.
> Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions
Zimbra is urging customers to apply updates to address a critical security vulnerability impacting the Classic Web Client that could result in arbitrary code execution. The vulnerability has been described as a case of stored cross-site scripting (XSS) that could allow specially crafted emails to e...
> CVE-2026-59922 Mistune plugins/formatting: quadratic-time parsing on long runs of `~~x~~`, `==x==`, and `^^x^^` markers (strikethrough / mark / insert)
Information published.
> CVE-2026-58251 NATS Server: Queue Subscribe Authz Bypass
Information published.
> US cyber agency CISA had to build its incident playbook during the incident, agency reveals
CISA said it "missed" an opportunity to get ahead of the security incident by not creating a response plan ahead of time.
> CVE-2026-58207 NATS Server: Remote crash via integer overflow in Connz pagination
Information published.
> CVE-2026-59890 setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+
Information published.
> Nihon Kotsu
La société japonaise Nihon Kotsu, l'un des plus grands opérateurs de taxis du Japon, a confirmé avoir subi un accès non autorisé à ses systèmes internes et une infection par un logiciel malveillant. L'incident, découvert le 11 juillet, a conduit à l'isolement immédiat des systèmes affectés (tels que...
> CVE-2026-59930 Mistune toc / TableOfContents directive: heading IDs use predictable `toc_N` numbering with no slugification, allowing collision with attacker-controlled `id="toc_N"` content
Information published.
> CVE-2026-59925 inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs
Information published.
> Solid Advance Co., Ltd.
Solid Advance Co., Ltd. a détecté une infection par un logiciel malveillant sur certains de ses systèmes internes suite à un accès non autorisé depuis l'extérieur. En réponse, l'entreprise a mis en place des mesures d'urgence, notamment la coupure du réseau, ce qui a entraîné la suspension de certai...
> CVE-2026-59928 Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitions
Information published.
> CVE-2026-14739 DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders
Information published.
> Slackware p11-kit Addresses Critical Stack Overflow Issue 2026-191-01
New p11-kit packages are available for Slackware 15.0 and -current to fix a security issue.
> CVE-2026-59926 Mistune: XSS via unescaped class option in Admonition directive
Information published.
> CVE-2026-14740 DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment
Information published.
> No Manners Here: The Ruthless Rise of The Gentlemen Ransomware
Unit 42 explores The Gentlemen ransomware operations, revealing the affiliate model driving its rapid growth. Learn more here. The post No Manners Here: The Ruthless Rise of The Gentlemen Ransomware appeared first on Unit 42.
> CVE-2026-14380 DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile
Information published.
> CVE-2026-14461 Out-of-bound read in mtr
Information published.