[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (1 articles)

|

// AI-powered summary generated at 04:00

> The fake report message that ends with a stolen Reddit account
A direct message arrives on Reddit from a stranger, and it invites a reply. That reply is the point. This scheme runs on social engineering, with no malware and no malicious links, and it has spread across Reddit, Discord, and similar platforms. The goal is a single piece of information: a login or...
> Top AI Agents Built to Catch Malicious Code Can Be Tricked Into Running It
Ask an AI coding agent to scan open-source code for security holes, and it might run the attacker's code on your own machine instead. That is the finding in a proof-of-concept published Wednesday by the AI Now Institute, an attack it calls "Friendly Fire." It works against Anthropic's Claude Code a...
> Open-source collaboration is growing worldwide and putting pressure on maintainers
Developers are pushing code and opening pull requests across economy borders at a rate GitHub has rarely seen. Outbound collaboration, the sum of git pushes and pull requests sent from developers in one economy to public repositories in another, grew by 16% from Q4 2025 to Q1 2026, according to the...
> Outlook va proposer des réponses automatiques basées sur des règles
Outlook va permettre de créer des réponses automatiques basées sur des règles, avec modèles et conditions. pour ne plus répondre pareil à tout le monde. Le post Outlook va proposer des réponses automatiques basées sur des règles a été publié sur IT-Connect.
> Unpatched Backdoor in Tenda Firmware Grants Admin Access to Devices
Tracked as CVE-2026-11405, the vulnerability allows unauthenticated attackers to access a device's web management interface. The post Unpatched Backdoor in Tenda Firmware Grants Admin Access to Devices appeared first on SecurityWeek.
> Product showcase: Protect your iPhone with McAfee Mobile Security
McAfee Mobile Security for iOS combines scam protection, web protection, VPN, Wi-Fi security, and device security checks in a single app. It is also available for Android. After downloading the app from the App Store, I created an account and completed a short onboarding process. The app asks whethe...
> Why AI Governance Without Guardrails Is Theater
> Wireshark 4.6.7 patches a dozen security flaws
Network analysts who open packet captures in Wireshark push untrusted data through a large set of protocol dissectors, and each parser is a spot where a malformed frame can trip up the software. The 4.6.7 maintenance release closes twelve of those weak points. The fixes reach from cellular signaling...
> Messaging fraud trends point to smarter attacks, stronger blocking
Fraudsters spent 2025 investing in scale. New routes, new tools, and higher message volumes moved through the SMS, voice, and chat channels that businesses rely on to reach customers. Money follows that activity. The Communications Fraud Control Association puts global telecom fraud losses at around...
> GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents
Researchers at Wiz found that a flaw in six popular AI coding assistants lets a booby-trapped code project quietly take control of a developer's computer. The assistant asks permission to edit one harmless-looking file, but the write lands on a sensitive one instead. The affected tools are Amazon Q...
> Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodes
Cybersecurity researchers have disclosed details of a new threat actor dubbed Lurking Lizard that has been operating an end-to-end malicious residential proxy business using an infrastructure comprising more than 230 lookalike domains. The activity dates back to at least August 2022, according to D...
> A single malware file can outweigh an entire AI dataset
Antivirus vendors and security startups keep shipping AI features that promise to read malware the way a seasoned analyst would. The results inside security teams tell a quieter story. A new paper argues that static analysis of software, the job of deciding whether a program is malicious by examinin...
> ISC Stormcast For Thursday, July 9th, 2026 https://isc.sans.edu/podcastdetail/10000, (Thu, Jul 9th)
> _HELP_ME_ESCAPE_FROM_BELARUS_PLEASE_ [Guest Diary], (Tue, Jul 7th)
[This is a Guest Diary by Jason Callahan, an ISC intern as part of the SANS.edu BACS program]
> Loyalist College
Le Loyalist College fait face à des problèmes techniques majeurs à l'échelle de l'établissement, ayant mis hors service ses systèmes, services, internet et courriels. Un membre du personnel a indiqué à Quinte News que la perturbation était due à une menace cybernétique provenant d'une source externe...
> Stiftung Wagerenhof
La Fondation Wagerenhof, une institution pour personnes handicapées à Uster, a été victime d'une cyberattaque par ransomware. L'attaque, qui a eu lieu le 9 juillet, a bloqué l'accès à ses systèmes informatiques et chiffré des données. Bien que la fondation refuse de payer la rançon, elle anticipe un...
> Not-so-anonymous telemetry: The @injectivelabs/sdk-ts backdoor
A malicious commit disguised as SDK telemetry briefly compromised @injectivelabs/sdk-ts, exfiltrating wallet mnemonics and private keys.
> Greene County
Le comté de Greene, en Géorgie, a dû mettre hors ligne son réseau gouvernemental après avoir découvert un incident de cybersécurité le 9 juillet. Cet incident a perturbé le traitement des paiements et les services des bureaux fiscaux, judiciaires et administratifs. Les spécialistes en cybersécurité...
> Kaneko
La société Kaneko a annoncé avoir été victime d'une infection par rançongiciel sur certains de ses serveurs. L'accès non autorisé a été détecté le 9 juillet 2026. La société a immédiatement isolé son réseau externe et a mis en place un comité de crise. Bien que l'accès non autorisé aux données opéra...
> Multiples vulnérabilités dans Google Chrome (09 juillet 2026)
De multiples vulnérabilités ont été découvertes dans Google Chrome. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.