De multiples vulnérabilités ont été découvertes dans Google Chrome. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.
De multiples vulnérabilités ont été découvertes dans WordPress. Elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données, une injection de code indirecte à distance (XSS) et un contournement de la politique de sécurité.
In this post, we examine two vibe-coded credential harvesting platforms, Loot and UltraVault, and the Amazon Bedrock abuse used to validate stolen secrets.
Une vulnérabilité a été découverte dans Kaspersky Secure Mail Gateway. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance.
De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.
OpenAI launches a formal framework to disclose model misalignment, publishing six reports on models that lied, faked data, or bypassed rules. Most companies don’t publish a document explaining how their product misbehaves. OpenAI just did. On September 16, it released a formal framework for tracking...
USN-8779-1 introduced a regression in Bubblewrap
Plugin4Shell attack affects all the major coding agents, researchers say
USN-8779-1 fixed vulnerabilities in Bubblewrap. Unfortunately, the fix for
CVE-2026-87766 introduced a regression in symlink resolution, preventing
certain Flatpak applications from launching. This update reverts that fix
until a complete fix is available.
We apologize for the inconvenience.
Origi...
Cross-environment attacks demand a new approach to security operations. Learn how Unit 42 Managed XSIAM helps SOC teams investigate complete attack paths.
The post Inside the Modern SOC: Defending the Cross-Environment Pivot appeared first on Unit 42.
A new Android malware called RatHat has been discovered, targeting users with an AI-powered subsystem that helps operators remotely navigate compromised devices. [...]
European organizations can run AI workloads on Amazon Web Services (AWS) while keeping data within the European Union (EU) and meeting regulatory requirements. You can now run generative AI workloads on open weight models on Amazon Bedrock in the AWS European Sovereign Cloud. We’re excited to announ...
Cisco released patches for an actively exploited authentication bypass vulnerability in its Cisco Identity Services Engine (ISE) platform, which is used for enterprise network access control and policy enforcement. This is the second zero-day flaw Cisco has been forced to rele...
The latest zero-day has a maximum-severity rating and affects Cisco Identity Services Engine, a product hit with three actively exploited vulnerabilities since June 2025.
The post Cisco alerts customers to second actively exploited zero-day in as many days appeared first on CyberScoop.
Several security issues were fixed in Bubblewrap.
The proposal, known as the EU KIDS Act, would block social media platforms from offering accounts to children younger than 13 and establish a bloc-wide minimum age of 15 for account creation.
How malicious Chrome extensions steal passwords, drain cryptocurrency wallets and display fake ClickFix instructions, and what to do if you find one of these extensions installed in your browser.
Wordfence Argus discovered a PHP Object Injection vulnerability in Tutor LMS, affecting more than 100,000 WordPress sites. Subscriber-level attackers could achieve remote code execution. Update to version 4.0.8 as soon as possible.
The post 100,000 WordPress Sites Exposed to Remote Code Execution vi...
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. For the stable distribution (trixie), these problems have been fixed in version 153.0.8010.47-2~deb13u1.
A California law that prohibits teens from receiving recommended social media content from other social media users violates their First Amendment rights, EFF argued this week.
The case, Meta v. Bonta, challenges SB 976, which requires that teen social media users get their parents’ permission befor...