[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (1 articles)

|

// AI-powered summary generated at 04:00

> Five Foxes Co., LTD.
Five Foesx a annoncé que certains de ses serveurs de siège social ont potentiellement été infectés par un rançongiciel. L'incident a été détecté lors d'une enquête de sécurité le 8 juillet 2026. Pour contenir la propagation, l'entreprise a immédiatement arrêté ses serveurs, ses fonctions Internet et...
> Pushpanjali Hospital Research Center Private Limited et Pushpanjali Group
Le centre de recherche Pushpanjali Hospital, situé à Delhi Gate, Agra, et le groupe Pushpanjali ont été victimes d'une cyberattaque par rançongiciel (ransomware) visant à obtenir une rançon. L'attaque a verrouillé les données importantes, les fichiers de sauvegarde et le logiciel téléphonique du ser...
> Multiples vulnérabilités dans Joomla! (08 juillet 2026)
De multiples vulnérabilités ont été découvertes dans Joomla!. Certaines d'entre elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données, une atteinte à l'intégrité des données et une injection de code indirecte à distance (XSS).
> Multiples vulnérabilités dans les produits HPE Aruba Networking (08 juillet 2026)
De multiples vulnérabilités ont été découvertes dans les produits HPE Aruba Networking. Elles permettent à un attaquant de provoquer un déni de service à distance, une atteinte à la confidentialité des données et un contournement de la politique de sécurité.
> Ville de Carros
La Ville de Carros a confirmé être victime d'une cyberattaque qui a rendu son site internet municipal indisponible. Les équipes techniques travaillent au rétablissement des services, mais la nature exacte de l'attaque et l'existence d'une fuite de données n'ont pas été confirmées. Les démarches admi...
> Multiples vulnérabilités dans les produits Foxit (08 juillet 2026)
De multiples vulnérabilités ont été découvertes dans les produits Foxit. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et une atteinte à la confidentialité des données.
> Coordinated GitHub API enumeration and access token abuse
Datadog Security Research has tracked multiple coordinated campaigns enumerating GitHub organizations, repositories, and users through the public GitHub API, abusing leaked access tokens, and cloning private repositories.
> [webapps] Joomla Page Builder CK 3.5.10 - Arbitrary File Upload
Joomla Page Builder CK 3.5.10 - Arbitrary File Upload
> [webapps] Langflow 1.9.0 - RCE
Langflow 1.9.0 - RCE
> Oracle Linux 9 Grafana-pcp Important Security Issue ELSA-2026-35829
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
> [webapps] Atarim WordPress Plugin 4.2.2 - Sensitive Information Exposure
Atarim WordPress Plugin 4.2.2 - Sensitive Information Exposure
> [webapps] Krayin CRM v2.2.x - Authenticated Remote Code Execution
Krayin CRM v2.2.x - Authenticated Remote Code Execution
> Oracle grafana-pcp Important Security Update ELSA-2026-35831
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
> Oracle Linux 9 Ruby Important Command Injection DoS Fix ELSA-2026-33577
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
> Accenture confirms breach after hacker offers stolen data for sale
IT services giant Accenture has confirmed it suffered a security breach after a threat actor claimed to have stolen 35 GB of source code and other data from the company. [...]
> Oracle Grafana Important Update CVE-2026-39821 ELSA-2026-35828
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
> Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation
A cybercrime campaign combined a loader-as-a-service framework and DLL sideloading via a Go-compiled fake MpClient.dll, a novel evasion layer combination. The post Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation appeared first on Unit 42.
> Spain arrests suspected hacker linked to Russian hacktivist campaign
Authorities didn’t name the man or file formal charges, but accuse him of participating in attacks linked to Cyber Army of Russia Reborn and NoName. The post Spain arrests suspected hacker linked to Russian hacktivist campaign appeared first on CyberScoop.
> 16-year-old KVM flaw allows attackers to escape VMs and take over Linux servers
A critical vulnerability in the Kernel-based Virtual Machine (KVM) module of the Linux kernel allows attackers with root access in a guest VM to execute arbitrary code on the host system. This violates the most important security boundary that cloud providers and enterprises r...
> Slackware tftp-hpa Moderate Path Bypass Buffer Overflow Fix 2026-188-01
New tftp-hpa packages are available for Slackware 15.0 and -current to fix security issues.