[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> Multiples vulnérabilités dans Google Chrome (18 septembre 2026)
De multiples vulnérabilités ont été découvertes dans Google Chrome. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.
> Multiples vulnérabilités dans WordPress (18 septembre 2026)
De multiples vulnérabilités ont été découvertes dans WordPress. Elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données, une injection de code indirecte à distance (XSS) et un contournement de la politique de sécurité.
> Attacker infrastructure, but vibe-coded: tracking the evolution of credential harvesting platforms
In this post, we examine two vibe-coded credential harvesting platforms, Loot and UltraVault, and the Amazon Bedrock abuse used to validate stolen secrets.
> Vulnérabilité dans Kaspersky Secure Mail Gateway (18 septembre 2026)
Une vulnérabilité a été découverte dans Kaspersky Secure Mail Gateway. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance.
> Multiples vulnérabilités dans les produits IBM (18 septembre 2026)
De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.
> OpenAI admits its models lie to cover their own mistakes
OpenAI launches a formal framework to disclose model misalignment, publishing six reports on models that lied, faked data, or bypassed rules. Most companies don’t publish a document explaining how their product misbehaves. OpenAI just did. On September 16, it released a formal framework for tracking...
> Ubuntu 26.04 Bubblewrap Low Regression Issue USN-8779-2
USN-8779-1 introduced a regression in Bubblewrap
> AI coding agents' 0-click RCE flaw could hand attackers keys to the kingdom
Plugin4Shell attack affects all the major coding agents, researchers say
> USN-8779-2: Bubblewrap regression
USN-8779-1 fixed vulnerabilities in Bubblewrap. Unfortunately, the fix for CVE-2026-87766 introduced a regression in symlink resolution, preventing certain Flatpak applications from launching. This update reverts that fix until a complete fix is available. We apologize for the inconvenience. Origi...
> Inside the Modern SOC: Defending the Cross-Environment Pivot
Cross-environment attacks demand a new approach to security operations. Learn how Unit 42 Managed XSIAM helps SOC teams investigate complete attack paths. The post Inside the Modern SOC: Defending the Cross-Environment Pivot appeared first on Unit 42.
> New RatHat Android malware uses AI to automate device control
A new Android malware called RatHat has been discovered, targeting users with an AI-powered subsystem that helps operators remotely navigate compromised devices. [...]
> Run open weight models on Amazon Bedrock in AWS European Sovereign Cloud
European organizations can run AI workloads on Amazon Web Services (AWS) while keeping data within the European Union (EU) and meeting regulatory requirements. You can now run generative AI workloads on open weight models on Amazon Bedrock in the AWS European Sovereign Cloud. We’re excited to announ...
> Cisco patches max-severity ISE flaw, the second critical zero-day this week
Cisco released patches for an actively exploited authentication bypass vulnerability in its Cisco Identity Services Engine (ISE) platform, which is used for enterprise network access control and policy enforcement. This is the second zero-day flaw Cisco has been forced to rele...
> Cisco alerts customers to second actively exploited zero-day in as many days
The latest zero-day has a maximum-severity rating and affects Cisco Identity Services Engine, a product hit with three actively exploited vulnerabilities since June 2025. The post Cisco alerts customers to second actively exploited zero-day in as many days appeared first on CyberScoop.
> Ubuntu 26.04 Bubblewrap Notable Denial of Service Vulnerability USN-8779-1
Several security issues were fixed in Bubblewrap.
> European Commission set to push social media restrictions, safety requirements into law
The proposal, known as the EU KIDS Act, would block social media platforms from offering accounts to children younger than 13 and establish a bloc-wide minimum age of 15 for account creation.
> Malicious Chrome and Edge add-ons: how to spot them and why they’re dangerous | Kaspersky official blog
How malicious Chrome extensions steal passwords, drain cryptocurrency wallets and display fake ClickFix instructions, and what to do if you find one of these extensions installed in your browser.
> 100,000 WordPress Sites Exposed to Remote Code Execution via PHP Object Injection Vulnerability Found by Wordfence Argus in Tutor LMS
Wordfence Argus discovered a PHP Object Injection vulnerability in Tutor LMS, affecting more than 100,000 WordPress sites. Subscriber-level attackers could achieve remote code execution. Update to version 4.0.8 as soon as possible. The post 100,000 WordPress Sites Exposed to Remote Code Execution vi...
> Debian Chromium Critical Code Execution Denial of Service DSA-6506-1
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. For the stable distribution (trixie), these problems have been fixed in version 153.0.8010.47-2~deb13u1.
> California’s “Addictive Feeds” Law Violates Teens’ First Amendment Rights
A California law that prohibits teens from receiving recommended social media content from other social media users violates their First Amendment rights, EFF argued this week. The case, Meta v. Bonta, challenges SB 976, which requires that teen social media users get their parents’ permission befor...