[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (14 articles)

|

// AI-powered summary generated at 08:00

> The modern CISO is becoming the next CFO
At some point, every security leader gets asked a version of the same question: Are we good? It tends to arrive when something is at stake and the person asking needs to know they can rely on the answer. I learned what that question really means at a firm I was with earlier...
> CVE-2026-8926 password leak with netrc and user in URL
Information published.
> CVE-2026-9080 UAF after pause in socket callback
Information published.
> Oracle Linux 8 Ruby Important DoS Fixes Advisory ELSA-2026-33515
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
> CVE-2026-8458 wrong reuse for different services
Information published.
> CVE-2026-10536 HTTP/2 stream-dependency tree UAF
Information published.
> Oracle Linux 8 Kernel Important Threats Advisory ELSA-2026-50374
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
> CVE-2026-8286 wrong STARTTLS connection reuse
Information published.
> CVE-2026-9545 exposing HTTP/3 early data
Information published.
> AI-Generated Malware Powers New Armored Likho APT Campaign
Armored Likho APT uses AI-generated malware, phishing, and BusySnake Stealer to target governments and power grids in Russia, Kazakhstan, and Brazil. Kaspersky’s threat research team has documented a previously unknown APT group they’re calling Armored Likho, also tracked under the name Eagle Werewo...
> CVE-2026-8932 incomplete mTLS config matching in conn reuse
Information published.
> CVE-2026-8924 trailing dot domain super cookie
Information published.
> Hackers Exploit Maximum Severity Adobe ColdFusion Flaw
Threat actors are exploiting an Adobe ColdFusion vulnerability which has a CVSS score of 10.0
> BeyondTrust warns of critical flaws in remote access software
BeyondTrust warned customers to patch two critical security flaws in its Remote Support (RS) and Privileged Remote Access (PRA) software that could allow attackers to bypass authentication. [...]
> CVE-2026-55952 TLS 1.3 server denial of service via malformed ClientHello pre-shared key extension
Information published.
> CVE-2026-54886 SSH SFTP server denial of service via extended channel data infinite loop
Information published.
> Windows 11 : avec Cloud rebuild, Microsoft réinstalle votre PC depuis le cloud, même s’il ne démarre plus
Microsoft teste Cloud rebuild sur Windows 11 : réinstallation complète de l'OS et des pilotes via Windows Update, sans clé USB, même si le PC ne démarre plus. Le post Windows 11 : avec Cloud rebuild, Microsoft réinstalle votre PC depuis le cloud, même s’il ne démarre plus a été publié sur IT-Connect...
> CVE-2026-12480 Arbitrary HDF5 File Read via Virtual Dataset Bypass in keras-team/keras
Information published.
> CVE-2026-14647 onnx onnxruntime old.cc convPoolShapeInference_opset19 out-of-bounds
Information published.
> Microsoft testing new Cloud Rebuild Windows 11 recovery feature
Microsoft has begun testing the Cloud Rebuild recovery feature in the latest Windows 11 Insider Preview builds released for users in the Experimental channel. [...]