[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (111 articles)

|

// AI-powered summary generated at 16:00

> UODO - autorité polonaise
La Commission européenne a initié une procédure d'infraction (INFR(2026)2130) contre la Pologne en raison de l'absence de dispositions garantissant une surveillance adéquate du traitement des données personnelles dans les domaines de l'ordre public et de la justice.Cette procédure fait suite à de mu...
> PIPC - autorité sud-coréenne
L'autorité sud-coréenne sanctionne trois entreprises pour des manquements graves et élémentaires en matière de sécurité, notamment l'absence de restriction d'accès par adresse IP aux interfaces d'administration et l'utilisation d'une authentification faible, ayant conduit à d'importantes violations...
> New Helix vishing group emerges in SharePoint data theft attacks
A new data-extortion group called Helix is using identity-focused tactics such as voice phishing (vishing), device code phishing, and multi-factor authentication (MFA) abuse to steal data from SharePoint environments. [...]
> Ubuntu 16.04 Expat Important Denial of Service CVE-2026-41080 USN-8520-1
Expat could be made to crash if it received specially crafted input.
> Ubuntu 16.04 Python Critical Denial of Service Vulnerability USN-8524-1
Python could be made to crash if it received specially crafted input.
> Microsoft expects more Windows security updates from AI-discovered flaws
Microsoft says Windows users should expect to see an increase in security updates as the company increasingly relies on artificial intelligence to discover vulnerabilities in its codebase. [...]
> npm 12 Disables Install Scripts by Default to Reduce Supply Chain Risk
GitHub has officially announced the release of npm version 12 with install scripts disabled by default, along with deprecating granular access tokens (GATs) designed to bypass two-factor authentication (2FA). The Microsoft-owned subsidiary noted that the following npm install behaviors that used to...
> FFE : une nouvelle fuite massive Ă  la veille des Championnats de France
Une revendication attribuée à un pirate vise la Fédération française d’équitation, avec des données exposées et un message politique assumé en plein Championnats de France d’équitation.
> What are the worst spyware apps — and how do you spot them?
Spyware apps are designed to go undetected. Here are the 3 worst spy app types, how to detect them, and how to protect your device.
> EU 'Chat Control' snoopfest returns after vote to kill it falls short
Opponents won the count but missed the 360-seat threshold needed to stop the interim CSAM-scanning rule
> How to password protect an Excel file
A step-by-step guide on how to password protect an Excel file on Windows, Mac, and other ways to keep your files secure and private.
> How World Cup crypto prediction sites take your money
Crypto prediction games promise easy wins, but some are little more than token sales or outright scams. Here's what to look for.
> USN-8524-1: Python vulnerability
It was discovered that Python did not use sufficient entropy for Expat hash-flooding protection in the xml.parsers.expat and xml.etree.ElementTree modules. An attacker could use this to cause a denial of service via a crafted XML document.
> How to create a professional email address with a custom domain
Learn how to create a business email address, compare custom domain against provider options, and see examples.
> ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories
Most security mess starts as admin work. A link gets clicked. A tool gets trusted. A bucket name gets reused. A setting stays loose because nobody wants to touch it. This week is full of that kind of damage. Not loud. Not clever. Just small gaps doing big jobs. The worst part is how normal it all l...
> 6.9 million driver’s license numbers stolen from AssuranceAmerica
Millions of AssuranceAmerica customers are being notified after attackers accessed driver's license numbers and other personal information.
> QIZ Security Raises $17 Million for Cryptographic Governance Platform
The Israeli company has developed a cryptographic posture and post-quantum cryptography management platform. The post QIZ Security Raises $17 Million for Cryptographic Governance Platform appeared first on SecurityWeek.
> GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware
GigaWiper is a destructive backdoor that combines multiple wiping and ransomware-like capabilities into a single operational platform. This blog analyzes how the malware incorporates code from several previously separate malware families and provides guidance to help defenders detect and defend agai...
> New Forg365 phishing platform uses AI to target Microsoft 365 accounts
A new phishing-as-a-service (PhaaS) operation called Forg365 focuses on stealing Microsoft 365 accounts by combining adversary-in-the-middle (AiTM) and device code methods with AI-assisted lure generation. [...]
> 764 splinter group leader sentenced to 40 years in jail
Alexis Chavez coerced multiple girls to commit self harm and produce child sexual abuse material for notoriety in a sprawling violent extremist collective affiliated with the Com. The post 764 splinter group leader sentenced to 40 years in jail appeared first on CyberScoop.