[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (36 articles)

|

// AI-powered summary generated at 12:00

> Les Rencontres du Clusif 2026
📅 1er juillet 2026 📍 Lieu Pavillon RoyalCarrefour du Bout des Lacs75016 Paris Intervenants Anne Le HĂ©nanffMinistre dĂ©lĂ©guĂ©e chargĂ©e de l’Intelligence artificielle et du NumĂ©rique Etienne BusnelExpert Technique Cyber Assurance BessĂ© Joseph GraceffaPrĂ©sident du Clusir Nord de France Seynabou DiopFou...
> USN-8512-1: Gzip vulnerabilities
It was discovered that Gzip's gzexe utility handled temporary files in an insecure manner. When the mktemp utility was not available, gzexe constructed a temporary file path based on the process ID, which could be predicted. A local attacker could possibly use this issue to overwrite arbitrary files...
> Choose your WhatsApp username carefully
WhatsApp is introducing usernames to help protect your phone number. Just make sure you don't undermine that privacy by choosing the wrong one.
> Proof-of-Concept Exploit Released for Linux ‘Bad Epoll’ Root Access Vulnerability
Organizations are urged to patch after proof-of-concept code makes the Linux root escalation flaw easier to exploit. The post Proof-of-Concept Exploit Released for Linux ‘Bad Epoll’ Root Access Vulnerability appeared first on SecurityWeek.
> Dawarich : l’alternative open source et auto-hĂ©bergĂ©e Ă  Google Timeline
Google Maps Timeline a disparu du web et votre historique de localisation s'efface ? Dawarich, alternative open source et auto-hĂ©bergĂ©e, prend le relais. Le post Dawarich : l’alternative open source et auto-hĂ©bergĂ©e Ă  Google Timeline a Ă©tĂ© publiĂ© sur IT-Connect.
> USN-8511-1: socat vulnerabilities
It was discovered that socat incorrectly handled the SOCKS5 proxy server reply parser. A remote attacker could possibly use this issue to execute arbitrary code. (CVE-2026-56123) It was discovered that socat incorrectly handled a sample script. A local attacker could possibly use this issue to over...
> Brit supermarket giant triples down on facial recog to nab shoplifters
Up to 150 more stores to get the 'Orwellian' tech by year's end
> Ubuntu 20.04 LTS ncurses Critical DoS Vulnerability USN-8503-1
ncurses could be made to crash if it opened a specially crafted file.
> Cavern Manticore: Exposing Iran-Linked Modular C2 Framework
Key Points Introduction Since early 2026, Check Point Research (CPR) has tracked a new modular command-and-control framework used by Cavern Manticore, an Iran-nexus APT group primarily targeting Israeli organizations, with a focus on IT providers, and government sectors. Cavern Manticore is an Iran...
> 6th July – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 6th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES River Bank & Trust, a US financial institution, has experienced a ransomware incident after an unauthorized actor accessed the network of parent compa...
> USN-8510-1: tar vulnerability
It was discovered that tar incorrectly handled symlinks when extracting archives. An attacker could possibly use this issue to overwrite arbitrary files.
> NetNut botnet takes a hit. Don’t be part of the next one.
Google, the FBI, and other partners have disrupted a residential proxy network built on millions of hijacked devices and used by criminals.
> USN-8509-1: Python vulnerabilities
It was discovered that Python incorrectly normalized paths in the tarfile module. An attacker could possibly use this issue to bypass path restrictions. This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2025-13462) It was discovered that Python's HTMLParser incorrectly handled ce...
> ISC Stormcast For Monday, July 6th, 2026 https://isc.sans.edu/podcastdetail/9994, (Mon, Jul 6th)
> Infosec News Nuggets — July 6, 2026
SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation A high-severity SharePoint Server flaw enabling remote code execution through deserialization of untrusted data was added to a federal known-exploited-vulnerabilities catalog after evidence surfaced that attackers are actively...
> This AI agent autonomously hacked a network, adapted on the fly, and demanded a ransom
A fully autonomous AI agent conducted an end-to-end cyber intrusion and extortion campaign after exploiting a vulnerable Langflow server, demonstrating how large language models could accelerate ransomware operations, according to research published by Sysdig. Sysdig detail...
> How to Evaluate an AI SOC Platform in 2026: 6 Capabilities That Separate Leaders from Bolt-On AI solutions
Building a shortlist for an AI SOC evaluation can be tough. SIEM, SOAR, and pureplay AI SOC vendors are all saying the same thing. But behind the identical label sit very different products, from chat assistants bolted onto a legacy SIEM to agent platforms that run detection, triage, investigation,...
> Prompt Injection Attacks Trick AI Agents Into Making Crypto Payments
Researchers uncovered two campaigns embedding indirect prompt injections in malicious websites to exploit autonomous AI agents browsing the web. The post Prompt Injection Attacks Trick AI Agents Into Making Crypto Payments appeared first on SecurityWeek.
> USN-8506-1: Request Tracker vulnerabilities
Aleksander Iwicki discovered that Request Tracker did not properly sanitize the search "Page" URL parameter. A remote attacker could possibly use this issue to conduct a reflected cross-site scripting attack. (CVE-2026-6841) It was discovered that Request Tracker did not properly sanitize user- con...
> USN-8505-1: Parsl vulnerability
It was discovered that Parsl incorrectly constructed SQL queries using unsafe string formatting with user-supplied input in the parsl-visualize component. A remote attacker could possibly use this issue to perform SQL injection attacks, leading to data exfiltration or a denial of service.