[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (111 articles)

|

// AI-powered summary generated at 16:00

> Ubuntu 26.04 curl Security Advisory USN-8525-1 Critical Risks and Fixes
Several security issues were fixed in curl.
> Ubuntu 26.04 LTS libheif Major Denial of Service Vulnerabilities USN-8526-1
Several security issues were fixed in libheif.
> Injective SDK on npm infected with cryptocurrency wallet stealer
Hackers compromised the Injective Labs SDK project's GitHub repository and used it to publish a malicious package on the Node Package Manager (npm) that stole cryptocurrency wallet private keys and mnemonic seed phrases. [...]
> Ubuntu 26.04 LTS libsoup Faces Critical Session Hijacking and DoS Issues
Several security issues were fixed in libsoup.
> USN-8526-1: libheif vulnerabilities
Xianrui Dong discovered that libheif had an out-of-bounds read in its HEIF sequence track parser. An attacker could possibly use this issue to cause a denial of service or obtain sensitive information. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-47254) Junyi Liu discovered that libheif had...
> USN-8525-1: curl vulnerabilities
Harry Sintonen discovered that curl incorrectly handled credentials when following HTTP redirects in conjunction with .netrc files. An attacker could possibly use this issue to obtain sensitive information. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS. (CVE-2024-...
> WolfSSL, GeoVision, VTK vulnerabilities
Cisco Talos’ Vulnerability Discovery & Research team recently disclosed three vulnerabilities in WolfSSF, fourteen in GeoVision, and one vulnerability in VTK-DICOM.The vulnerabilities mentioned in this blog post have been patched by their respective vendors, in adherence to Cisco’s third-party v...
> Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs
Datadog Security Labs is warning of "several overlapping campaigns" that are systematically enumerating corporate GitHub organizations, repositories, and user accounts through the GitHub API. "Operators rely on automated scraping tooling with custom or legitimate-sounding user agents, leveraging Gi...
> European Commission Chooses to Keep EU Users Locked Up Behind Big Tech’s Gates
Users are always seeking more control over their social networking experience to make it better, whether to improve privacy or enhance flexibility. Interoperability between social networking platforms like Facebook and TikTok has so many benefits that solve those issues.   Say you’re on multiple pla...
> GodDamn Ransomware Uses PoisonX to Blind Security Software
GodDamn ransomware uses the signed PoisonX driver to disable security tools, marking a more advanced version of the Beast ransomware family. Symantec’s Threat Hunter Team found a new ransomware family called GodDamn that first appeared in the wild on May 21, 2026, and analyzed an attack that took pl...
> New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware
Microsoft has taken apart a destructive Windows backdoor it calls GigaWiper. What stands out is how it is built: not one tool but three older destructive programs bolted into one, offered as commands the operator can choose from. Each is a different way to break a machine: wipe the whole disk, over...
> Winning 54% of the time
With Wimbledon's help, Hazel argues against the popular myth that "Attackers only need to be right once, but defenders need to be right 100% of the time."
> Cour de Justice de l'UE
La Cour de justice de l'Union européenne a clarifié l'articulation entre le RGPD et la liberté d'expression, jugeant qu'une législation nationale ne peut exclure l'application du règlement pour une base de données de condamnations pénales qui ne poursuit pas une finalité journalistique.L'affaire éma...
> AEPD - autorité espagnole
Le non-respect du délai de réponse à une demande d'accès à des enregistrements de vidéosurveillance, entraînant leur suppression, constitue une double violation du droit d'accès (article 15) et du droit à la limitation du traitement (article 18), la conservation des images étant justifiée par l'inté...
> Interpol cybercrime crackdown nets 5,800 arrests across 97 countries
The anti-fraud crackdown, dubbed Operation First Light, identified more than 142,000 victims of various social-engineering scams. The post Interpol cybercrime crackdown nets 5,800 arrests across 97 countries appeared first on CyberScoop.
> AP - autorité néerlandaise
L'autorité néerlandaise de protection des données (AP) recommande aux fournisseurs et utilisateurs de systèmes d'intelligence artificielle d'adhérer à un code de bonnes pratiques publié par la Commission européenne, détaillant les futures obligations de transparence.À compter du 2 août 2026, de nouv...
> GPDP - autorité italienne
L'autorité italienne de protection des données (GPDP) a sanctionné la société Character Technologies, Inc. pour de multiples manquements liés à son service d'intelligence artificielle générative, notamment en matière de transparence, de protection des mineurs et de licéité de l'entraînement de ses m...
> New Helix vishing group emerges in SharePoint data theft attacks
A new data-extortion group called Helix is using identity-focused tactics such as voice phishing (vishing), device code phishing, and multi-factor authentication (MFA) abuse to steal data from SharePoint environments. [...]
> CNIL
La Commission Nationale de l'Informatique et des Libertés (CNIL) rappelle les conditions de licéité encadrant la mise en place par un employeur de dispositifs de contrôle de l’activité de son personnel.Un tel dispositif doit respecter trois conditions cumulatives pour être licite. Premièrement, il d...
> AEPD - autorité espagnole
L'autorité espagnole de protection des données (AEPD) a publié une décision constatant une infraction de l'Université Complutense de Madrid (UCM) pour des manquements en lien avec le principe de minimisation des données, suite à la divulgation de la condition de victime de violence de genre d'une ca...