[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (36 articles)

|

// AI-powered summary generated at 12:00

> Debian BIRD3 Denial of Service Vulnerabilities DSA-6379-1
Multiple security vulnerabilities were discovered in the BIRD internet routing daemon, which could result in denial of service. For the stable distribution (trixie), this problem has been fixed in version 3.1.7-0+deb13u1. We recommend that you upgrade your bird3 packages.
> Debian Stable Chromium Important Arbitrary Code Exec Information DSA-6378-1
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. For the stable distribution (trixie), these problems have been fixed in version 150.0.7871.46-1~deb13u1.
> Week in review: SimpleHelp vulnerability exploited, Oracle EBS Payments flaw under attack
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Companies keep bolting AI onto their products, and the security bill is coming due Companies keep bolting AI and LLM features onto their products, and the security results are starting to show a pattern...
> Security Affairs newsletter Round 584 by Pierluigi Paganini – INTERNATIONAL EDITION
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. U.S. Government Agency Paid $1M to Data Extortion...
> Slackware 15.0 libseccomp Moderate Security Fix Double Free 2026-183-01
New libseccomp packages are available for Slackware 15.0 and -current to fix security issues.
> Slackware 15.0 libevent Important Security Fix 2026-182-01
New libevent packages are available for Slackware 15.0 and -current to fix security issues.
> MSGás
La MSGás, compagnie de gaz de l'État de Mato Grosso do Sul, a notifié ses clients d'un incident de cybersécurité. Un attaque par ransomware a potentiellement exposé des données personnelles telles que le nom, le CPF et l'adresse. La compagnie a pris des mesures pour isoler les systèmes, révoquer les...
> Slackware Mozilla-Thunderbird Significant Security Update 2026-182-02
New mozilla-thunderbird packages are available for Slackware 15.0 and -current to fix security issues.
> Police du Kerala
Une enquête a été lancée suite au dysfonctionnement d'une application interne liée au site web de la Police du Kerala, qui gère les fichiers internes. Les autorités soupçonnent une cyberattaque, bien que la police ait affirmé qu'aucune fuite de données n'a eu lieu. L'application est hors service dep...
> Comté de Pennington
Le comté de Pennington, dans le Dakota du Sud, est en train de gérer un incident de cybersécurité affectant certaines parties de son réseau. En réponse, la plupart des bureaux publics du comté seront fermés le lundi 6 juillet, tandis que les autorités travaillent à la restauration sécurisée des syst...
> U.S. Government Agency Paid $1M to Data Extortion Group Kairos
A U.S. government agency paid $1M to Kairos, a group focused on data theft and extortion rather than ransomware, Ransom-ISAC reports. A new case study from Ransom-ISAC reconstructs a complete data-extortion incident involving a U.S. government body and a threat actor called Kairos, using a leaked ne...
> Alibaba reportedly bans employees from using Claude Code
Alibaba has reportedly classified Claude Code as high-risk software.
> JadePuffer ransomware used AI agent to automate entire attack
Researchers identified what they believe is the first documented case of a ransomware operation, JadePuffer, conducted entirely by a large language model (LLM) agent. [...]
> U.S. Government Entity Paid Kairos $1 Million in Data-Theft Extortion Case
A U.S. government entity paid about $1 million to keep stolen files from being leaked, according to a new case study by Rakesh Krishnan for Ransom-ISAC, built on a leaked negotiation chat and the blockchain trail the payment left. The odd part: the group that took the money calls itself Kairos, but...
> Debian php8.4 Critical Memory Corruption DSA-6377-1 CVE-2026-14355
It was discovered that a buffer overflow in the implementation of AES Key Wrap with Padding in the openssl extension of PHP, a widely-used open source general purpose scripting language, could result in memory corruption. For the stable distribution (trixie), this problem has been fixed in
> North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign
The North Korean threat actors linked to the Contagious Interview campaign have been observed publishing 108 unique packages and web browser extensions spanning npm, Packagist, Go, and Google Chrome as part of an ongoing activity referred to as PolinRider. "The campaign remains active, and new mali...
> Security Roundup: Apple’s Hide My Email Service Fails to Hide Your Email
Plus: Alleged Scattered Spider hacking member extradited, dozens of license plate reader errors, and Indian officials are concerned about WhatsApp’s username rollout.
> Confidential computing's core trust mechanism is broken. The fix may not exist
Attested TLS: the handshake that can't prove who's on the other end
> CVE-2026-53223 net: guard timestamp cmsgs to real error queue skbs
Information published.
> FBI: TeamPCP Compromised Dev Tools to Steal Cloud Credentials
FBI says TeamPCP poisoned trusted developer tools to steal cloud credentials, spread malware through software updates, and extort victims. On July 2, 2026, the FBI published a FLASH alert identifying the criminal group called TeamPCP and detailing how it compromised widely used developer and securit...