> TODAY'S SUMMARY (36 articles)
Today's cybersecurity landscape highlights significant threats and vulnerabilities. A major incident involved hackers hijacking Microsoft's official X account to promote a cryptocurrency scheme, showcasing the ongoing risks of social media exploitation. Additionally, a critical zero-day vulnerability in Fortinet's FortiMail is actively being exploited, prompting urgent action from users and inclusion in the U.S. CISA's Known Exploited Vulnerabilities catalog. On the espionage front, a China-aligned group has been phishing AI policy experts by impersonating US officials, emphasizing the trend of targeting high-profile individuals. Meanwhile, AI agents are increasingly being linked to SQL injection attacks against government sites, raising concerns about the security of AI applications. Lastly, law enforcement has made arrests in the KillSec ransomware group, reflecting ongoing efforts to combat cybercrime.
|
// AI-powered summary generated at 12:00
Une vulnérabilité a été découverte dans PostgreSQL JDBC. Elle permet à un attaquant de provoquer un contournement de la politique de sécurité.
Ce bulletin d'actualité du CERT-FR revient sur les vulnérabilités significatives de la semaine passée pour souligner leurs criticités. Il ne remplace pas l'analyse de l'ensemble des avis et alertes publiés par le CERT-FR dans le cadre d'une analyse de risques pour prioriser l'application des...
This post continues and concludes our series on Agent ID, by outlining steps that an administrator or security team can take to secure blueprints and agent identities created in their local Entra ID tenant.
WordPress Plugin WPZOOM Portfolio 1.4.21 - Reflected Cross-Site Scripting (XSS)
Windows Defender (MsMpEng.exe) - Race Condition
It was discovered that SOGo did not properly sanitize categories used
for events, tasks, and contacts. A remote authenticated attacker could
possibly use this issue to perform cross-site scripting attacks. This
issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04
LTS, and Ubuntu 26.0...
KNX visualisering - Broken Access Control
KeepInMind 0.8.4.2 - Stored XSS
New php82 packages are available for Slackware 15.0 to fix a security issue.
MEmu Android Emulator 9.2.7.0 - Local Privilege Escalation
Pulpy 0.1.1-Beta - Filesystem Sandbox Bypass
Open source antivirus scanning sits inside mail gateways, file upload checks, and endpoint tooling at organizations of every size. Much of that work runs through ClamAV, the scanning engine maintained by Cisco’s Talos group. The project released two patch versions, 1.5.3 and 1.4.5, carrying fixes fo...
Joomla Extension 4.1.4 - PHP Object injection
New mutt packages are available for Slackware 15.0 and -current to fix a security issue.
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks. For the stable distribution (trixie), these problems have been fixed in version 6.12.95-1.
Multiple security issues were discovered in MediaWiki, a website engine for collaborative work, which could result in information disclosure, code execution via unsafe deserialisation or cross-site scripting. For the stable distribution (trixie), these problems have been fixed in version 1:1.43.9+df...
Medtronic says a ShinyHunters attack exposed the personal and medical data of over 3.8 million people. Products and operations were unaffected. Medtronic is notifying 3,834,294 individuals after a cyberattack by the ShinyHunters extortion group exposed personal and medical information. In April 2026...
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Hijacked npm Packages Use Novel VSCode Autorun and Blockchain Dead Drops to Deploy a Credential/Crypto Stealer  Building a CI/CD pipeline for Sigm...
Financial institutions are putting their clients at risk in the name of convenience.
Flipper Devices says development of the Flipper Zero firmware will continue, albeit with a smaller internal team and greater reliance on community contributions. [...]