[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (143 articles)

|

// AI-powered summary generated at 20:00

> Multiples vulnérabilités dans les produits Palo Alto Networks (09 juillet 2026)
De multiples vulnérabilités ont été découvertes dans les produits Palo Alto Networks. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.
> Multiples vulnérabilités dans les produits Juniper Networks (09 juillet 2026)
De multiples vulnérabilités ont été découvertes dans les produits Juniper Networks. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, un déni de service à distance et une atteinte à la confidentialité des données.
> Greene County
Le comté de Greene, en Géorgie, a dû mettre hors ligne son réseau gouvernemental après avoir découvert un incident de cybersécurité le 9 juillet. Cet incident a perturbé le traitement des paiements et les services des bureaux fiscaux, judiciaires et administratifs. Les spécialistes en cybersécurité...
> Smashing Security podcast #475: JadePuffer – the AI that ran a ransomware attack all by itself
A 15-year-old boy asked a chatbot for help - and cancelled nearly 47,000 anime streaming subscriptions in under four hours. Meanwhile, researchers have documented the first fully autonomous, agentic AI-driven ransomware attack, "JadePuffer". What does this tell us about the future of cybersecurity?...
> "We Want Texans to Know Their Rights": Q&A with Mayday Health on the Impact of Surveillance on Abortion Care
Last May, EFF reported that a sheriff’s office in Texas searched data from more than 83,000 automated license plate reader (ALPR) cameras to track down a woman suspected of self-managing an abortion. ALPRs are promoted as tools for keeping communities safe by finding missing persons and locating sto...
> GitHub’s public APIs are becoming an enterprise reconnaissance tool
GitHub continues to be a scintillating target for attackers because it sits in the middle of the software supply chain and gives threat actors three things they crave: source code, secrets, and automated pipelines to run amok in. Datadog Security Research has been tracking...
> Slackware proftpd Critical Stack Overflow Advisory 2026-189-02
New proftpd packages are available for Slackware 15.0 and -current to fix security issues.
> Slackware xorg-server Critical Use-After-Free and Overflow Vuln 2026-189-03
New xorg-server packages are available for Slackware 15.0 and -current to fix security issues.
> Suspected Chinese snoops caught breaking into universities' Roundcube mailservers
Proofpoint researcher tells The Reg: 'We estimate the total volume of targets would be a few dozen'
> Slackware 15.0 libXfont2 Critical Heap Overflow Fix 2026-189-01
New libXfont2 packages are available for Slackware 15.0 and -current to fix security issues.
> Ubuntu 26.04 LTS mailcap Critical Remote Code Execution USN-8518-1
mailcap could allow applications to escape sandbox restrictions
> Debian pgextwlist SQL Injection Risk Fix DSA-6385-1 CVE-2023-39417
Guillaume Winter discovered that pgextwlist, an extension for PostgreSQL implementing a whitelist mechanism for PostgreSQL extensions, was susceptible to SQL injection via crafted schema and user names. For the stable distribution (trixie), this problem has been fixed in version 1.19-1+deb13u1.
> Mount Royal University confirms breach as hackers claim attack
Mount Royal University in Calgary says hackers stole and then deleted data from its file storage systems after breaching the university's network. [...]
> Ubiquiti Patches Critical UniFi OS Flaws Allowing Command Injection and Privilege Escalation
Ubiquiti patched seven UniFi OS flaws, including critical CVE-2026-50746, which allows command injection in UniFi Connect Application. Ubiquiti released security updates for seven critical UniFi OS vulnerabilities, including a maximum-severity flaw, tracked as CVE-2026-50746 (CVSS score of 10.0), en...
> Greek victims file lawsuit against Intellexa over Predator spyware
The use of the spyware came to light in 2022, with traces of Predator found on dozens of phones. The scandal led to the resignation of Greece’s intelligence service chief and the prime minister’s chief of staff.
> Cash App owner to pay $45 million to settle allegations of lax security
State attorneys general announced the bipartisan agreement with Block, Inc. on Wednesday, saying that the company incorrectly promised users that Cash App offered the same protections as a bank.
> Fake Paysafe, Skrill SDKs on NPM and PyPi steal credentials
Malicious packages on the Node Package Manager (npm) and the Python Package Index (PyPI) delivered stealer malware to developers and users of Paysafe, Skrill, and Neteller payment applications. [...]
> Oracle Linux 9 ELSA-2026-36195 389-ds-base Important Heap Overflow
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
> Oracle 9 FreeIPMI Moderate Security Advisory ELSA-2026-36210
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
> GitHub Copilot: Sorry Dave, I can't do that harmful thing - unless you ask me in code
More fun with AI jailbreaks, this time at the workflow level