L'autorité espagnole sanctionne une entreprise pour avoir utilisé un système de vidéosurveillance captant des images de la voie publique et des zones de repos des employés, en violation du principe de minimisation des données.Faits et contexteL'Agence Espagnole de Protection des Données (AEPD) a auj...
Le Comité européen de la protection des données (CEPD) a publié une mise à jour de son recueil thématique de décisions relatives à l'exercice des droits d'opposition et d'effacement.Cette publication, qui s'appuie sur le registre public des décisions prises par les autorités de contrôle chef de file...
Multiple vulnerabilities were discoverd in Nginx, a high-performance web and reverse proxy server, which could result in remote code execution, denial of service or memory disclosure. For the stable distribution (trixie), these problems have been fixed in version 1.26.3-3+deb13u7.
La Commission nationale de l'informatique et des libertés (CNIL) a publié une recommandation encadrant l'utilisation des données de localisation issues des véhicules connectés par les professionnels.Ce document, destiné aux constructeurs, gestionnaires de flotte, fournisseurs de télématiques et agré...
L'autorité espagnole de protection des données (AEPD) a sanctionné un gestionnaire de clubs de sport pour avoir réalisé une analyse d'impact relative à la protection des données (AIPD) non conforme pour son système de contrôle d'accès par empreinte digitale, qui affecte 95 000 utilisateurs.Faits et...
Microsoft announced today that it is accelerating its quantum-safe security roadmap, saying advances in quantum computing are bringing the need to replace today's encryption standards sooner than previously expected. [...]
L'Inspection estonienne de la protection des données (AKI) a publié une synthèse des évolutions législatives européennes dans le domaine numérique et de leur interaction avec la protection des données.Le Comité européen de la protection des données (CEPD), avec la participation de l'AKI, a approuvé...
La Cour suprême des États-Unis a jugé que la Commission fédérale du commerce (FTC) n'était plus indépendante, remettant en cause le fondement du Cadre de protection des données UE-États-Unis.Dans l'affaire Trump c. Slaughter, la Cour a statué que l'indépendance de la FTC était inconstitutionnelle, e...
Scammers wasted no time exploiting Venezuela's devastating earthquake, with researchers uncovering 212 newly-registered relief-themed domains in just five days.
Read more in my article on the Hot for Security blog.
A campaign active since last November has been targeting Python developers building Telegram bots with trojanized Pyrogram forks that allow attackers to read arbitrary files on compromised servers. [...]
DHS Secretary Markwayne Mullin has been floating the idea of adding back 600 CISA personnel after deep Trump administration cuts.
The post Trump budget boss Russell Vought open to re-staffing CISA appeared first on CyberScoop.
Scammers are using Amazon and the promise of big money to lure people in to their trap.
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a SimpleHelp flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a SimpleHelp flaw, tracked as CVE-2026-48558 (CVSS score v3.1 of 10.0), to its Known Exploited Vu...
29% of security pros were open to fully autonomous pentesting last year; now only 9% are
CIA Director John Ratcliffe said artificial intelligence capabilities are "akin to digital nuclear weapons.”
We’re accelerating quantum-safe readiness—and sharing what organizations can do now to transition earlier and with confidence.
The post Accelerating the quantum-safe timeline appeared first on Microsoft Security Blog.
New Microsoft research shows how attackers can hijack AI agents that act on a user's behalf, using nothing more than a poisoned tool description to make the agent quietly hand over company data to an outsider.
The trick is that the agent never breaks a rule. Every step looks routine, so in a defaul...
A new two-stage malware family called RustDuck is hijacking home routers, IP cameras, Android boxes, and poorly secured servers, then stitching them into a network built to knock websites and online services offline.
Researchers at QiAnXin's XLab have tracked it since February 2026, and say the rea...
Ex-employee claims this 'meets the definition of an insider threat'
Ruby could allow unintended access to network services.