[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (114 articles)

|

// AI-powered summary generated at 20:00

> CVE-2026-56406 libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.
Information published.
> CVE-2026-14258 Dhcpcd: dhcpcd infinite loop and out-of-bounds read via zero-length ipv6 nd option in router advertisement handling
Information published.
> PamStealer Uses Fake Maccy Sites and PAM Checks to Steal Mac Login Passwords
Cybersecurity researchers have flagged a new macOS information stealer called PamStealer that employs a series of clever tricks to infect systems and siphon sensitive data. The stealer, discovered by Jamf Threat Labs, is distributed as a compiled AppleScript (.scpt) file impersonating Maccy, a legi...
> CVE-2026-53043 ocfs2/dlm: validate qr_numregions in dlm_match_regions()
Information published.
> CVE-2026-56149 Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of Service
Information published.
> Government and Healthcare Are the Weakest Links in Global Email Security
Government and healthcare sectors have weak email security. Many domains lack SPF, DMARC, DKIM, and MTA-STS, leaving them open to phishing attacks. Comparitech analyzed live DNS records for 5,849 domains across 13 sectors and scored each one out of 8 points based on four standard email authenticatio...
> CVE-2026-53357 Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del()
Information published.
> CVE-2026-49090 Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service
Information published.
> Critical Cursor AI IDE Flaws Could Lead to OS-Level Remote Code Execution
The DuneSlide vulnerabilities enable zero-click prompt injection attacks that escape Cursor's sandbox and execute arbitrary code on the underlying operating system. The post Critical Cursor AI IDE Flaws Could Lead to OS-Level Remote Code Execution appeared first on SecurityWeek.
> PamStealer : ce malware macOS valide votre mot de passe avant de le voler
PamStealer, un infostealer macOS déguisé en Maccy, présente la particularité de valider le mot de passe via PAM avant de voler cookies et identifiants. Le post PamStealer : ce malware macOS valide votre mot de passe avant de le voler a été publié sur IT-Connect.
> Brave 1.92 – le multi-comptes natif avec les Containers
Brave 1.92 intègre nativement les Containers sur desktop : des onglets cloisonnés pour rester connecté à plusieurs comptes d'un même site, sans extension. Le post Brave 1.92 – le multi-comptes natif avec les Containers a été publié sur IT-Connect.
> Swimming Pools, Pee, and Trying to Delete Your Data From the Internet
Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSiteI can't recall if someone else originally came up with this saying or if I said it in some off-the-cuff comment and it just propagated, but since it's o...
> Intezer helps SOC teams automate custom security tasks
Intezer has announced Custom Agents, a new capability that lets security teams build their own AI agents directly inside the Intezer platform. The launch builds on Intezer’s core approach, that lets autonomous agents do the security work and humans supervise it. Security teams can no longer rely on...
> User swore hacker called General Failure had invaded his PC
Maybe they were looking for Private Data
> OpenVPN : 7 failles corrigées, risque de crash du serveur
OpenVPN 2.7.5 corrige sept vulnérabilités : use-after-free, fuites mémoire et débordements de tampon, dont plusieurs peuvent faire planter un serveur VPN. Le post OpenVPN : 7 failles corrigées, risque de crash du serveur a été publié sur IT-Connect.
> Non-interactive SSH attacks dominate after login
Anyone who runs a server with SSH exposed to the internet sees the same pattern in the logs. A steady stream of automated scanners tries to log in, hour after hour, from addresses all over the world. The common picture of what comes next has an attacker landing a shell, looking around the system, an...
> Politician who investigated spyware abuses had his phone hacked with Pegasus spyware
A government customer of NSO Group used the company's Pegasus spyware to hack into the phone of a European politician, who at the time was serving on an EU committee tasked with investigating the spyware industry.
> Spyware found on phone of European Parliament member probing it
Stelios Kouloglou, formerly a member of the European Parliament's committee investigation abuses of commercial spyware, was twice infected with Pegasus while serving, researchers said.
> EU Politicians Investigated Pegasus Spyware. Then It Ended Up on One of Their Phones
“It is a direct attack on the rule of law,” says one European Parliament member of the new findings from Citizen Lab.
> Someone infected a spyware probe overseer with spyware
Citizen Lab says the phone of a member of Europe’s PEGA Committee was infected twice with Pegasus, the NSO Group spyware that gave the panel its name. The post Someone infected a spyware probe overseer with spyware appeared first on CyberScoop.