[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (57 articles)

|

// AI-powered summary generated at 12:00

> ‘HalluSquatting’ Turns AI Hallucinations Into Botnet Delivery Mechanism
Researchers demonstrate adversarial hallucination squatting against popular AI assistants to achieve remote code execution. The post ‘HalluSquatting’ Turns AI Hallucinations Into Botnet Delivery Mechanism appeared first on SecurityWeek.
> GigaWiper Merges Three Malware Families Into One Destructive Backdoor
Microsoft uncovered GigaWiper, a modular Go backdoor combining three malware families with espionage, remote control, and destructive wiping features. In October 2025, Microsoft’s threat intelligence team identified destructive wiping activity inside compromised environments and traced it to a previ...
> Former ransomware negotiator gets 4 years for BlackCat attacks
A former employee of cybersecurity incident response company DigitalMint was sentenced to 70 months in prison for targeting U.S. companies in BlackCat (ALPHV) ransomware attacks. [...]
> Ransomware Negotiator Gets 70 Months in Prison for Aiding BlackCat Attacks
A 41-year-old former ransomware negotiator has been sentenced to nearly six years (i.e., 70 months) in prison in the U.S. for their role in conspiring with the now-defunct BlackCat ransomware operators to extort multiple victims and working with two other cybersecurity professionals to target additi...
> CVE-2026-56289 Loop with Unreachable Exit Condition in GNU patch
Information published.
> CVE-2026-59818 etcd: gRPC client listener does not enforce `--client-crl-file` certificate revocation
Information published.
> Network of 200 GitHub Repositories Used for Malware Infection
A Go module is used to load PowerShell code that fetches a resolver from public dead drops to execute Windows malware. The post Network of 200 GitHub Repositories Used for Malware Infection appeared first on SecurityWeek.
> CVE-2026-56288 NULL Pointer Dereference in GNU patch
Information published.
> Chatto passe en open source : un seul binaire pour remplacer Teams, Slack et Discord ?
Hendrik Mans a publié le code source de Chatto, une messagerie d'équipe auto-hébergée qui tient en un seul binaire pour remplacer Discord, Teams ou Slack. Le post Chatto passe en open source : un seul binaire pour remplacer Teams, Slack et Discord ? a été publié sur IT-Connect.
> July 2026 Patch Tuesday forecast: Is CVE tracking still practical?
I was off by a month in my forecast of record-setting CVE releases from Microsoft. In June, we saw the deluge of over 200 reported CVEs that I expected in May. There were 116 CVEs for Windows 11 and 104 for Windows 10. In addition, we saw large numbers in both common applications like Office and Sha...
> Workato expands Agent Studio with Headless API, AI guardrails
Workato has announced two new capabilities for Agent Studio: Headless API and Agent Guardrails. Headless API lets Genies, Workato’s AI agents built on Agent Studio, be embedded into any business application surface, on web, mobile, or inside another agent’s own environment. Agent Guardrails are conf...
> Check Point CTO Jonathan Zanger sees AI elevating the value of cyber
Check Point Software CTO Jonathan Zanger met with CSO Spain during the software company’s Engage 2026 user conference last week in Paris. At the event, Check Point executives and representatives discussed how the company is dealing with various types of threats, how it is a...
> The open source library holding up your stack might have one maintainer
Every serious software product runs on code that someone else wrote and released for free. A web service leans on a cryptography library, a data pipeline pulls in a parser, and a mobile app ships a handful of small utilities that one person maintains in spare time. All of it carries the same label....
> Microsoft prévient : l’IA va faire gonfler vos Patch Tuesday
Microsoft prévient que le volume de correctifs par Patch Tuesday va augmenter : son système MDASH découvre désormais les failles de Windows à l'aide de l'IA. Le post Microsoft prévient : l’IA va faire gonfler vos Patch Tuesday a été publié sur IT-Connect.
> Most data brokers won’t tell you what happened to your deletion request
Data brokers collect personal details on most adults in the United States and sell them to buyers that include employers, landlords, insurance companies, and government agencies. California gives residents a way to push back. You can ask a broker to delete your records, or to stop selling and sharin...
> DEBULL : ce kit de phishing détourne le device code de Microsoft 365 pour contourner le MFA
ZeroBEC a repéré DEBULL, un kit de phishing qui abuse du device code Microsoft pour pirater des comptes Microsoft 365 sans voler de mot de passe. Le post DEBULL : ce kit de phishing détourne le device code de Microsoft 365 pour contourner le MFA a été publié sur IT-Connect.
> Microsoft is rewriting Windows patch guidance because of AI
Microsoft is recommending that organizations shorten Windows update deployment timelines, warning that advances in AI are reducing the time attackers need to identify and exploit vulnerabilities after security updates are released. The company says organizations should reassess how quickly they roll...
> Turning software supply chain security into a daily habit
In this Help Net Security video, Anastasia Tikhonova, Global Threat Research Lead at Group-IB, explains how to operationalize software supply chain risk. Instead of filing an SBOM away as a compliance document, she argues teams should use it every day for vulnerability triage, vendor access reviews,...
> Microsoft 365 : pendant que la victime est au téléphone, l’attaquant crée sa propre passkey Entra
Depuis le printemps 2026, des pirates appellent des salariés sous prétexte d'enrôler une passkey Entra. Pendant ce temps, l'attaquant enregistre la sienne. Le post Microsoft 365 : pendant que la victime est au téléphone, l’attaquant crée sa propre passkey Entra a été publié sur IT-Connect.
> AWS gives its ERP agent deny-by-default rules and a separate identity
Accounts receivable teams at large companies spend hours each day matching incoming bank payments to invoices by hand. When those payments sit unmatched for days, cash flow suffers and days sales outstanding climbs. The same pattern repeats across blocked invoices, purchase order approval holds, mon...