[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (57 articles)

|

// AI-powered summary generated at 12:00

> CVE-2026-20215 ClamAV 7Zip File Format Processing Out-of-Bounds Memory Corruption Vulnerability
Information published.
> CVE-2026-20214 ClamAV FSG File Format Processing Out-of-Bounds Memory Corruption Vulnerability
Information published.
> Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions
Zimbra is urging customers to apply updates to address a critical security vulnerability impacting the Classic Web Client that could result in arbitrary code execution. The vulnerability has been described as a case of stored cross-site scripting (XSS) that could allow specially crafted emails to e...
> CVE-2026-59856 Vim: Arbitrary Code Execution via PHP Omni-Completion
Information published.
> US cyber agency CISA had to build its incident playbook during the incident, agency reveals
CISA said it "missed" an opportunity to get ahead of the security incident by not creating a response plan ahead of time.
> Nihon Kotsu
La société japonaise Nihon Kotsu, l'un des plus grands opérateurs de taxis du Japon, a confirmé avoir subi un accès non autorisé à ses systèmes internes et une infection par un logiciel malveillant. L'incident, découvert le 11 juillet, a conduit à l'isolement immédiat des systèmes affectés (tels que...
> Solid Advance Co., Ltd.
Solid Advance Co., Ltd. a détecté une infection par un logiciel malveillant sur certains de ses systèmes internes suite à un accès non autorisé depuis l'extérieur. En réponse, l'entreprise a mis en place des mesures d'urgence, notamment la coupure du réseau, ce qui a entraîné la suspension de certai...
> Slackware p11-kit Addresses Critical Stack Overflow Issue 2026-191-01
New p11-kit packages are available for Slackware 15.0 and -current to fix a security issue.
> No Manners Here: The Ruthless Rise of The Gentlemen Ransomware
Unit 42 explores The Gentlemen ransomware operations, revealing the affiliate model driving its rapid growth. Learn more here. The post No Manners Here: The Ruthless Rise of The Gentlemen Ransomware appeared first on Unit 42.
> New U-Boot flaws could enable stealthy firmware attacks
Six vulnerabilities in the widely used U-Boot bootloader have been discovered that could allow attackers to execute malicious code during device boot, potentially enabling stealthy firmware attacks that compromise security protections and install persistent malware. [...]
> Friday Squid Blogging: “Squidbleed” Vulnerability
In a rare combined cybersecurity/squid post, a twenty-nine-year-old squid proxy bug can leak HTTP requests. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.
> Datatilsynet - autorité norvégienne
L'autorité norvégienne de protection des données (Datatilsynet) a publié des orientations clarifiant les modalités d'exercice du droit d'accès des personnes concernées, notamment en ce qui concerne le format de la réponse fournie par le responsable du traitement.Suite à plusieurs demandes d'individu...
> AEPD - autorité espagnole
L'autorité espagnole sanctionne un particulier pour l'utilisation d'un système de vidéosurveillance dans une location touristique, jugeant que la finalité de sécurité n'était pas justifiée et que l'information fournie aux locataires était absente ou non conforme.Faits et contexteL'autorité espagnole...
> Update Now: Critical Zimbra Classic Web Client Flaw Could Expose Mailboxes
Zimbra addressed a critical stored XSS vulnerability in its Classic Web Client that lets malicious emails execute code when opened. Zimbra has released version 10.1.19 to fix a critical stored XSS vulnerability in its Classic Web Client, which is widely used to access Zimbra Collaboration. The flaw,...
> Armenian national pleads guilty to Ryuk ransomware attacks
Karen Vardanyan faces up to 15 years in federal prison and agreed to pay nearly $1.2 million in restitution. The post Armenian national pleads guilty to Ryuk ransomware attacks appeared first on CyberScoop.
> Europe revives law allowing big tech to scan for CSAM
The law known as Chat Control 2.0 passed in the European Parliament, permitting companies like Google, Meta and Microsoft to scan users' messages to hunt for CSAM.
> Debian opam Important Directory Traversal Fix DSA-6386-1 CVE-2026-57825
Kate Deplaix reported that .install file directives were insufficiently restricted in OPAM, a package manager for OCaml. Installing files through .install files did not check symlinks resolution on the target path, which could result in directory traversal out of the package area. For the stable dis...
> CISA looks to remedy ailments from big May credential leak
A major credential leak spurred the Cybersecurity and Infrastructure Security Agency to strengthen protections for its sensitive materials, improve how researchers can report agency vulnerabilities and develop plans for similar incidents, the agency said in a forensic report released Thursday. The b...
> Ryuk ransomware member pleads guilty in the US, faces 15 years in prison
A 34-year-old Armenian man has pleaded guilty to hacking U.S. companies and deploying the infamous Ryuk ransomware to encrypt their systems. [...]
> A GDPR compliance checklist for small and medium-sized businesses
A detailed GDPR compliance checklist for SMEs. Follow this UK GDPR checklist to meet GDPR requirements and implement compliance controls.