[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (57 articles)

|

// AI-powered summary generated at 12:00

> No Manners Here: The Ruthless Rise of The Gentlemen Ransomware
Unit 42 explores The Gentlemen ransomware operations, revealing the affiliate model driving its rapid growth. Learn more here. The post No Manners Here: The Ruthless Rise of The Gentlemen Ransomware appeared first on Unit 42.
> New U-Boot flaws could enable stealthy firmware attacks
Six vulnerabilities in the widely used U-Boot bootloader have been discovered that could allow attackers to execute malicious code during device boot, potentially enabling stealthy firmware attacks that compromise security protections and install persistent malware. [...]
> Friday Squid Blogging: “Squidbleed” Vulnerability
In a rare combined cybersecurity/squid post, a twenty-nine-year-old squid proxy bug can leak HTTP requests. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.
> Datatilsynet - autorité norvégienne
L'autorité norvégienne de protection des données (Datatilsynet) a publié des orientations clarifiant les modalités d'exercice du droit d'accès des personnes concernées, notamment en ce qui concerne le format de la réponse fournie par le responsable du traitement.Suite à plusieurs demandes d'individu...
> AEPD - autorité espagnole
L'autorité espagnole sanctionne un particulier pour l'utilisation d'un système de vidéosurveillance dans une location touristique, jugeant que la finalité de sécurité n'était pas justifiée et que l'information fournie aux locataires était absente ou non conforme.Faits et contexteL'autorité espagnole...
> Update Now: Critical Zimbra Classic Web Client Flaw Could Expose Mailboxes
Zimbra addressed a critical stored XSS vulnerability in its Classic Web Client that lets malicious emails execute code when opened. Zimbra has released version 10.1.19 to fix a critical stored XSS vulnerability in its Classic Web Client, which is widely used to access Zimbra Collaboration. The flaw,...
> Armenian national pleads guilty to Ryuk ransomware attacks
Karen Vardanyan faces up to 15 years in federal prison and agreed to pay nearly $1.2 million in restitution. The post Armenian national pleads guilty to Ryuk ransomware attacks appeared first on CyberScoop.
> Europe revives law allowing big tech to scan for CSAM
The law known as Chat Control 2.0 passed in the European Parliament, permitting companies like Google, Meta and Microsoft to scan users' messages to hunt for CSAM.
> Debian opam Important Directory Traversal Fix DSA-6386-1 CVE-2026-57825
Kate Deplaix reported that .install file directives were insufficiently restricted in OPAM, a package manager for OCaml. Installing files through .install files did not check symlinks resolution on the target path, which could result in directory traversal out of the package area. For the stable dis...
> CISA looks to remedy ailments from big May credential leak
A major credential leak spurred the Cybersecurity and Infrastructure Security Agency to strengthen protections for its sensitive materials, improve how researchers can report agency vulnerabilities and develop plans for similar incidents, the agency said in a forensic report released Thursday. The b...
> Ryuk ransomware member pleads guilty in the US, faces 15 years in prison
A 34-year-old Armenian man has pleaded guilty to hacking U.S. companies and deploying the infamous Ryuk ransomware to encrypt their systems. [...]
> A GDPR compliance checklist for small and medium-sized businesses
A detailed GDPR compliance checklist for SMEs. Follow this UK GDPR checklist to meet GDPR requirements and implement compliance controls.
> Destructive Windows backdoor stuffs multiple wipers and ransomware code into a single package
Microsoft says GigaWiper combines at least 3 malware families into one modular tool
> Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages
Unknown threat actors compromised the Injective Labs SDK project's GitHub repository and leveraged it to publish a malicious package on the npm registry to steal cryptocurrency wallet private keys and mnemonic seed phrases. The compromised version, @injectivelabs/[email protected], came embedded with...
> AssuranceAmerica : 6,99 millions de clients exposés
Un important assureur confirme une fuite touchant 6,99 millions de personnes et des permis de conduire exposés.
> Ryuk operator pleads guilty; Blackcat/AlphV conspirator gets nearly 6-year sentence
One man accused of deploying Ryuk ransomware pleaded guilty Wednesday in an Oregon federal court to conspiracy and computer fraud, while another man received a 70-month federal prison sentence in a Florida court for helping the Blackcat/AlphV gang extort multiple victims.
> Monero tracé dans une opération menée contre le dark web
La police relie des paiements Monero à 28 suspects arrêtés dans sept pays lors d’une opération internationale contre le dark web.
> License plate cameras may be next target after Supreme Court reins in location tracking
If a warrant is ultimately needed for ALPR searches, experts say, it would radically limit how the networks of cameras can be used and would change modern policing.
> Oracle Linux Tigervnc Important Security Advisory ELSA-2026-22456
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
> Oracle Linux 7 Advisory ELSA-2026-20590 xorg-x11-server Security Update
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: