[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> Chatto passe en open source : un seul binaire pour remplacer Teams, Slack et Discord ?
Hendrik Mans a publié le code source de Chatto, une messagerie d'équipe auto-hébergée qui tient en un seul binaire pour remplacer Discord, Teams ou Slack. Le post Chatto passe en open source : un seul binaire pour remplacer Teams, Slack et Discord ? a été publié sur IT-Connect.
> July 2026 Patch Tuesday forecast: Is CVE tracking still practical?
I was off by a month in my forecast of record-setting CVE releases from Microsoft. In June, we saw the deluge of over 200 reported CVEs that I expected in May. There were 116 CVEs for Windows 11 and 104 for Windows 10. In addition, we saw large numbers in both common applications like Office and Sha...
> Workato expands Agent Studio with Headless API, AI guardrails
Workato has announced two new capabilities for Agent Studio: Headless API and Agent Guardrails. Headless API lets Genies, Workato’s AI agents built on Agent Studio, be embedded into any business application surface, on web, mobile, or inside another agent’s own environment. Agent Guardrails are conf...
> Check Point CTO Jonathan Zanger sees AI elevating the value of cyber
Check Point Software CTO Jonathan Zanger met with CSO Spain during the software company’s Engage 2026 user conference last week in Paris. At the event, Check Point executives and representatives discussed how the company is dealing with various types of threats, how it is a...
> The open source library holding up your stack might have one maintainer
Every serious software product runs on code that someone else wrote and released for free. A web service leans on a cryptography library, a data pipeline pulls in a parser, and a mobile app ships a handful of small utilities that one person maintains in spare time. All of it carries the same label....
> Microsoft prévient : l’IA va faire gonfler vos Patch Tuesday
Microsoft prévient que le volume de correctifs par Patch Tuesday va augmenter : son système MDASH découvre désormais les failles de Windows à l'aide de l'IA. Le post Microsoft prévient : l’IA va faire gonfler vos Patch Tuesday a été publié sur IT-Connect.
> Most data brokers won’t tell you what happened to your deletion request
Data brokers collect personal details on most adults in the United States and sell them to buyers that include employers, landlords, insurance companies, and government agencies. California gives residents a way to push back. You can ask a broker to delete your records, or to stop selling and sharin...
> DEBULL : ce kit de phishing détourne le device code de Microsoft 365 pour contourner le MFA
ZeroBEC a repéré DEBULL, un kit de phishing qui abuse du device code Microsoft pour pirater des comptes Microsoft 365 sans voler de mot de passe. Le post DEBULL : ce kit de phishing détourne le device code de Microsoft 365 pour contourner le MFA a été publié sur IT-Connect.
> Microsoft is rewriting Windows patch guidance because of AI
Microsoft is recommending that organizations shorten Windows update deployment timelines, warning that advances in AI are reducing the time attackers need to identify and exploit vulnerabilities after security updates are released. The company says organizations should reassess how quickly they roll...
> Turning software supply chain security into a daily habit
In this Help Net Security video, Anastasia Tikhonova, Global Threat Research Lead at Group-IB, explains how to operationalize software supply chain risk. Instead of filing an SBOM away as a compliance document, she argues teams should use it every day for vulnerability triage, vendor access reviews,...
> Microsoft 365 : pendant que la victime est au téléphone, l’attaquant crée sa propre passkey Entra
Depuis le printemps 2026, des pirates appellent des salariés sous prétexte d'enrôler une passkey Entra. Pendant ce temps, l'attaquant enregistre la sienne. Le post Microsoft 365 : pendant que la victime est au téléphone, l’attaquant crée sa propre passkey Entra a été publié sur IT-Connect.
> AWS gives its ERP agent deny-by-default rules and a separate identity
Accounts receivable teams at large companies spend hours each day matching incoming bank payments to invoices by hand. When those payments sit unmatched for days, cash flow suffers and days sales outstanding climbs. The same pattern repeats across blocked invoices, purchase order approval holds, mon...
> Only 28% of financial workforce MFA is phishing-resistant
Passwords remain part of many workforce authentication flows in financial organizations, making phishing and credential theft major identity security risks, according to a new Secret Double Octopus report. Key challenges preventing universal implementation of phishing-resistant MFA (Source: Secret D...
> ISC Stormcast For Friday, July 10th, 2026 https://isc.sans.edu/podcastdetail/10002, (Fri, Jul 10th)
> New infosec products of the week: July 10, 2026
Here’s a look at the most interesting products from the past week, featuring releases from Attestiv, Automox, Codenotary, and First Recon AI. Codenotary launches AI security platform that learns from AI agent behavior Codenotary has announced AgentMon 3, the latest generation of its enterprise AI se...
> Microsoft warns customers AI will mean busier Patch Tuesdays
More patches mean more reasons to buy Redmond’s auto-patching tools
> Slackware Tigervnc Important Fix Buffer Overflow 2026-190-01
New tigervnc packages are available for Slackware 15.0 and -current to fix security issues.
> Former DigitalMint ransomware negotiator who duped clients sentenced to 70 months in jail
Angelo Martino exploited his insider position and fed confidential information to ransomware co-conspirators to extort a combined $75.3 million from five U.S.-based victims. The post Former DigitalMint ransomware negotiator who duped clients sentenced to 70 months in jail appeared first on CyberScoo...
> Multiples vulnérabilités dans Suricata (10 juillet 2026)
De multiples vulnérabilités ont été découvertes dans Suricata. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.
> Multiples vulnérabilités dans Microsoft Azure Linux (10 juillet 2026)
De multiples vulnérabilités ont été découvertes dans Microsoft Azure Linux. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.