[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (14 articles)

|

// AI-powered summary generated at 08:00

> 16-year-old KVM flaw allows attackers to escape VMs and take over Linux servers
A critical vulnerability in the Kernel-based Virtual Machine (KVM) module of the Linux kernel allows attackers with root access in a guest VM to execute arbitrary code on the host system. This violates the most important security boundary that cloud providers and enterprises r...
> Slackware tftp-hpa Moderate Path Bypass Buffer Overflow Fix 2026-188-01
New tftp-hpa packages are available for Slackware 15.0 and -current to fix security issues.
> Watch out for fake support calls in Microsoft Teams
Palo Alto Networks’ security division, Unit 42, is warning of yet another campaign targeting Microsoft Teams users. The new campaign begins with Teams users receiving an email asking if they would like to participate in a survey. If they open the attached PDF file, they wil...
> Critical Gitea Docker Bug Under Active Exploitation Exposes Repositories and Secrets
Attackers are exploiting a critical Gitea flaw (CVE-2026-20896) that bypasses authentication with a single HTTP header, exposing repositories and sensitive data. Sysdig researchers warn that attackers are actively exploiting a critical authentication bypass flaw, tracked as CVE-2026-20896 (CVSS scor...
> Debian Imagemagick Critical DoS Information Disclosure Vuln DSA-6383-1
Multiple security vulnerabilities were discovered in imagemagick, a software suite used for editing and manipulating digital images, which could lead to denial of service, information disclosure or potentially arbitrary code execution if malformed images are processed. For the stable distribution (t...
> Windows is watching: Anti-piracy tool fingers Scattered Spider suspect
Along with other telemetry, Windows GDID makes online activity more traceable
> Debian Postfix Denial of Service Threat Advisory DSA-6382-1
Multiple security vulnerabilities were discovered in the Postfix mail transport agent, which could result in denial of service. For the stable distribution (trixie), this problem has been fixed in version 3.10.12-0+deb13u2. We recommend that you upgrade your postfix packages.
> Deepfake CSAM lawsuit against xAI, Grok expands
Two new alleged victims detailed how Grok was used by friends and family to generate sexual images of them as minors. The suit also adds Stability AI as a defendant. The post Deepfake CSAM lawsuit against xAI, Grok expands appeared first on CyberScoop.
> GitHub AI agent leaks private repos when asked nicely
Per usual, there's no fix - or even any documentation - for GitLost
> Nayax visée par un « Syndicate » du cybercrime
Nayax visée par une revendication pirate massive : données de paiement, clients et risque cyber sous surveillance. 1 milliard de CB concernées ?
> Chinese hackers develop LONGLEASH malware to expand ORB network
Chinese hackers tracked as 'UAT-7810' are actively evolving their malware to expand their Operational Relay Box (ORB) network by compromising internet-facing networking devices, primarily unpatched Ruckus routers. [...]
> Spanish Police Arrest Man Linked to CARR, Z-Pentest, and NoName057(16)
Spain arrested a suspected CARR and Z-Pentest collaborator in an FBI-led probe for aiding pro-Russian hackers, coordinating attacks, and using crypto. Spanish National Police arrested a man in Palencia last March on charges of membership in and collaboration with a terrorist organization, glorifying...
> Enforce zero data retention on Amazon Bedrock with Bedrock Projects and service control policies
With the introduction of models that require data sharing with third-party providers—such as Claude Fable 5—organizations need a way to centrally enforce data retention policies. Amazon Bedrock gives you control over whether your prompts and model outputs are retained after an inference request comp...
> More Odd DNS Records: NIMLOC, (Tue, Jul 7th)
Yesterday, I talked about NAPTR records and how they are related to RCS. But there is another "odd" record that shows up in my DNS logs. This one isn&#;x26;#;39;t new, but I don&#;x26;#;39;t think I ever covered it: NIMLOC. At least that is what Zeek calls it. But let&#;x26;#;39;s see wh...
> How the Reddit and Discord false report scam steals accounts
Scammers are tricking Reddit and Discord users into handing over login codes by claiming they were involved in a false report.
> County Government Reportedly Paid $1 Million to Cyber Extortion Group
The alleged victim, believed to be a small Ohio county, reportedly paid the extortion group to prevent the public release of sensitive stolen data. The post County Government Reportedly Paid $1 Million to Cyber Extortion Group appeared first on SecurityWeek.
> Hidden backdoor in Tenda router firmware grants admin access
A hidden authentication backdoor has been found in multiple Tenda router firmware versions, potentially allowing an attacker to gain administrative access to the device's web management panel. [...]
> Critical Gitea Flaw Under Active Exploitation, Researchers Warn
Attackers are exploiting the critical Gitea vulnerability CVE-2026-20896 to bypass authentication with a single HTTP header and access vulnerable repositories and secrets. The post Critical Gitea Flaw Under Active Exploitation, Researchers Warn appeared first on SecurityWeek.
> CAI cloud worm gives competitors' malware the boot, then steals secrets and mines for coin
Dog-eat-dog world for credential-stealing attackers
> GPDP - autorité italienne
Sanction d'un établissement scolaire pour la communication non autorisée d'une note disciplinaire sur un élève, visible par toute la classe via le registre électronique, en raison d'une erreur de manipulation d'un enseignant.Faits et contexteL'autorité italienne de protection des données (GPDP) a au...