[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> Vulnérabilité dans Laravel (10 septembre 2026)
Une vulnérabilité a été découverte dans Laravel. Elle permet à un attaquant de provoquer une injection de code indirecte à distance (XSS).
> Vulnérabilité dans Metabase (10 septembre 2026)
Le 06 août 2026, Metabase a publié un avis de sécurité concernant une vulnérabilité critique permettant à un attaquant non authentifié de provoquer une injection SQL (SQLi) dans la base de donnée de l'application Metabase. Cette injection SQL permet d’obtenir les droits administrateur de...
> Anthropic reveals fourth likely crime committed by its AI
Claude's Felony Bench rap sheet is now as long as OpenAI's
> Smashing Security podcast #484: How websites are tracking you with silence
When a chap called Matt noticed his Bluetooth headphones wouldn't switch to his phone, he was surprised to realise the reason was a single AliExpress webpage sitting open in his browser - playing nothing at all, at zero volume. And yet somehow his hardware could hear it. Audio fingerprinting is one...
> Novel Blue Moon kit targeting Chrome and Windows reflects new reality of AI-driven exploits
Mind the patch gap, please and thank you
> OpenSSL’s new alpha build speeds up post-quantum crypto
The OpenSSL project released the first alpha of OpenSSL 4.1.0, giving developers an early look at a version built for encrypted communication over unreliable connections and faster post-quantum cryptography. This marks the opening test build for a version still months from general availability. The...
> Chromium: CVE-2026-85046 Type confusion in V8
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Google is aware that an exploit for CVE-2026-85046 exists in the wild.
> Oracle Linux 8 xmlrpc-c Important HTML Injection Fix ELSA-2026-64772-0
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
> Oracle Linux 8 ELSA-2026-64809-0 expat Moderate Out-of-Bounds Fix
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
> Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks
Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being actively exploited in attacks. [...]
> Oracle Linux perl-GD Critical Update CVE-2026-11526 ELSA-2026-49758
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
> Threat matrix: Mapping threats across cloud web applications
Microsoft introduces the Cloud Web Applications Threat Matrix, a MITRE ATT&CK-aligned framework that helps defenders understand, prioritize, and mitigate threats to cloud-hosted web apps and serverless platforms. The post Threat matrix: Mapping threats across cloud web applications appeared firs...
> AdaptHealth confirms 4.1 million people exposed in July cyberattack
Healthcare company AdaptHealth has confirmed that data of 4.1 million people was exposed in a cyberattack discovered in July that was attributed to the ShinyHunters threat group. [...]
> CISA head says agency must change quickly to prevent the 'worst that could happen'
CISA's cybersecurity, infrastructure security and emergency communications divisions are among the priorities as the agency fills vacancies created at the beginning of the Trump administration, acting director Nick Andersen says.
> Chinese espionage groups swarm to exploit triple-link chain of zero-days
Multiple China-aligned threat groups exploited the defects quickly to target various organizations. Proofpoint said the activity is ongoing and expects it to widen. The post Chinese espionage groups swarm to exploit triple-link chain of zero-days appeared first on CyberScoop.
> San Francisco Orders Meta to Stop ‘Allowing’ AI Child Abuse Ads
The City Attorney’s Office has asked Meta to explain how the harmful ads repeatedly ran on Facebook and Instagram. The company claims the ads are not under the city’s jurisdiction.
> Skullcandy Dime 3 earbuds expose users to Bluetooth hijacking
The Carnegie Mellon University CERT Coordination Center (CERT/CC) is warning that Skullcandy Dime 3 wireless earbuds accept Bluetooth pairing requests from nearby unpaired devices without requiring user interaction. [...]
> OFAC and DOJ Strike Xinbi, a Multibillion-Dollar Marketplace for Cybercriminals
Summary U.S. authorities have sanctioned Xinbi Guarantee, a major Chinese-language illicit marketplace that connects criminal networks with money laundering, scam… The post OFAC and DOJ Strike Xinbi, a Multibillion-Dollar Marketplace for Cybercriminals appeared first on Chainalysis.
> How The $320M Exploit of Liquid Network Went Down
Summary Purported white-hat hackers exploited the Liquid Network to withdraw $320 million in BTC from the network’s reserve. A vulnerability… The post How The $320M Exploit of Liquid Network Went Down appeared first on Chainalysis.
> Cops Play Hide and Seek About Using Spy Tech to Avoid Scrutiny and Bad PR
Law enforcement agencies across the country are increasingly relying on spying technologies—automated license plate readers (ALPR), cell-site simulators, and facial recognition, to name a few--causing an outcry in many communities where people are rightly concerned about the threat to civil rights a...