[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> USN-8743-1: PHP vulnerabilities
It was discovered that PHP incorrectly handled backslash escaping in the PostgreSQL extension. An attacker could use this issue to perform SQL injection attacks. (CVE-2026-17543) It was discovered that PHP incorrectly handled certain inputs to the bccomp() function. An attacker could use this issue...
> Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE
Check Point has patched two critical vulnerabilities in the way its firewall and management products handle VPN certificates. The company says both could allow an unauthenticated remote attacker to run code, but only "under specific conditions" that it has not described. One flaw affects Check Poin...
> PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances
A suspected Russian-speaking cyber actor has been attributed to the use of artificial intelligence (AI) to devise exploits targeting a recently disclosed pair of security flaws in PaperCut NG/MF and break into hundreds of instances. According to independent reports from Blackpoint Cyber and GreyNoi...
> USN-8737-2: GNU C Library vulnerabilities
USN-8737-1 fixed vulnerabilities in GNU C Library. This update provides the corresponding fixes for Ubuntu 24.04 LTS. Original advisory details: It was discovered that GNU C Library had a buffer overflow in the strfmon function when handling right-justification padding. An attacker could possib...
> Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks
The Gigabud banking trojan now installs a second Android app that creates a work profile on an infected phone and drops a tampered banking app inside it, security firm Group-IB said in a report published on September 9. A work profile is a separate space that Android typically reserves for employer...
> Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316)
State-sponsored and financially-motivated attackers are actively exploiting CVE-2026-20079, a critical authentication bypass vulnerability in Cisco Secure Firewall Management Center (FMC), which is used for centrally managing multiple Cisco Secure Firewall devices across a network. Two FMC vulnerabi...
> 4.1 Million Impacted by AdaptHealth Data Breach
In June 2026, hackers stole personal, health, and insurance information from AdaptHealth’s systems. The post 4.1 Million Impacted by AdaptHealth Data Breach appeared first on SecurityWeek.
> Microsoft says September updates fix mouse settings reset issues
Microsoft has fixed a known issue that wiped mouse settings on some Windows 11 systems after installing the KB5120998 August 2026 preview update. [...]
> ShieldCrash : cette nouvelle zero-day Microsoft Defender offre un accès système
L'exploit ShieldCrash contourne le correctif de Microsoft pour la faille ShieldBreak et permet de lire n'importe quel fichier sur Windows et Windows Server. Le post ShieldCrash : cette nouvelle zero-day Microsoft Defender offre un accès système a été publié sur IT-Connect.
> Update Chrome now to protect against an actively exploited vulnerability
Chrome issues another monster update, fixing an actively exploited V8 vulnerability and 229 other flaws.
> Ubuntu Flatpak File Access Deletion Issues CVE-2026-34078 CVE-2026-34079
Flatpak could be made to access files outside its sandbox or delete arbitrary files on the host.
> AIs Compress Exploit Timeline
Give an AI agent a mere rumor of an exploit, and it’s enough for them to find it. What’s worse, I found I could use my own agents to find the exploit just by knowing roughly what it was about and so could have been exploiting it well before the public patch was available! Given that just the rumour...
> CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026....
> InfoSec News Nuggets – 09/10/2026
Anthropic Discloses Fourth Cyber Incident in Alignment Assessment  Anthropic disclosed a fourth incident in which a Claude model gained unauthorized access to real third-party systems during a cybersecurity evaluation, a case its own July review had missed entirely. The newly found incident occurred...
> Scytale expands vendor risk management with AI-powered TPRM tools
Scytale has announced the launch of their latest AI-powered third-party risk management (TPRM) capabilities within its Vendors module. The release further extends vendor risk management from a periodic review exercise into a continuously updated vendor risk intelligence engine, giving security and G...
> ISC Stormcast For Thursday, September 10th, 2026 https://isc.sans.edu/podcastdetail/10088, (Thu, Sep 10th)
> WordPress adds automated security checks to block risky plugin releases
WordPress’ automated security review will now assess every plugin release before it is distributed through the WordPress.org update API. Releases considered a potential security risk will be blocked automatically. “A plugin can be secure today and introduce a vulnerability, or malicious code, in a f...
> Organizations Warned of Cisco Secure FMC Exploitation
Cisco and CISA have flagged exploitation of CVE-2026-20079, a vulnerability disclosed in March 2026. The post Organizations Warned of Cisco Secure FMC Exploitation appeared first on SecurityWeek.
> The longitude problem: In the AI era, detection is won on facts, not guesses
For most of the age of sail, a captain could find his latitude in minutes and could not find his longitude at all. Latitude you could read off the sun. Longitude, your position east to west, offered no such trick. Three weeks into the Atlantic, a navigator knew how far nort...
> Clearview AI Is Testing an AI Tool That Would Let Cops Unearth Your Life Online
InquiryIQ, a previously unreported prototype, tested a model from xAI, maker of Grok, to surface associates, social accounts, and other information about people identified through Clearview.