[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> Ubuntu 26.04 Tar Critical File Overwrite Threat USN-8477-1 CVE-2026-5704
tar could be made to overwrite files if it opened a specially crafted archive.
> House passes kids’ online safety bill, but Senate approval unlikely
The Kids Internet and Digital Safety (KIDS) Act passed with bipartisan support by a 267-117 margin, winning the two-thirds majority needed to greenlight the legislation under a process that speeds up a bill’s path to a vote but requires more than a simple majority.
> ​​What’s new in Microsoft Security: June 2026
This month’s updates help security and IT teams strengthen identity and multicloud foundations, protect data wherever it lives, and secure the developer workflows powering AI innovation. The post ​​What’s new in Microsoft Security: June 2026 appeared first on Microsoft Security Blog.
> Nissan Discloses Employee Data Breach Linked to Oracle Zero-Day
Nissan says employees' data was stolen via the Oracle PeopleSoft zero-day campaign
> Securing AI agents: When AI tools move from reading to acting
MCP tool poisoning turns trusted AI agents into a control plane for data loss. Learn how threat actors manipulate tool descriptions to trigger unauthorized actions, and how to detect, contain, and prevent it. The post Securing AI agents: When AI tools move from reading to acting appeared first on Mi...
> Hackers Steal Data of 4.38 Million Aflac Japan Customers
Hackers stole data from 4.38 million Aflac Japan customers after accessing its systems for 10 days before the breach was detected. Aflac Japan disclosed that hackers stole the personal information of 4.38 million customers and agents after gaining access to its systems between June 15 and June 25. A...
> Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints
Threat actors are continuing to exploit a critical Langflow vulnerability as part of fresh attacks designed to deliver a Monero cryptocurrency miner. The activity has been found to weaponize CVE-2026-33017 (CVSS score: 9.3), an unauthenticated remote code execution (RCE) vulnerability in Langflow,...
> Fake Perplexity extension on Chrome Web Store tracked searches
A malicious extension in the Chrome Web Store is masquerading as the Perplexity AI answer engine, intercepting search traffic and collecting browsing information. [...]
> Weekly Update 510: Live From Mallorca with Scott Helme
Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSiteHow's the view?! Back to business, it's now 8 years ago that Scott and I thought it would be a cool idea to build Why no HTTPS? We used the site to sham...
> Silent Swap Crypto Clipper Uses Fake Google Notes Extension to Replace Wallet Addresses
Cybersecurity researchers have flagged an active browser extension campaign that is designed to steal cryptocurrency by stealthily replacing wallet addresses when unsuspecting users initiate a transaction. The cryptocurrency clipper activity has been codenamed Silent Swap by McAfee Labs. "The camp...
> Critical SimpleHelp Vulnerability Exploited For Malware Delivery
Attackers exploited a critical SimpleHelp RMM bug to deploy TaskWeaver and Djinn Stealer malware
> DHS to unveil replacement council for critical infrastructure cybersecurity
The Department of Homeland Security is bringing back a key cybersecurity information sharing effort with critical infrastructure, more than a year after the Trump administration shuttered an existing nerve center between government and private sector. The Alliance of National Councils for Homeland O...
> Ubuntu 26.04 LTS libyang Critical Denial of Service USN-8485-1
libyang could be made to crash or run programs if it received specially crafted network traffic.
> Ubuntu 26.04 LTS libssh2 Important DoS Remote Code Exec USN-8486-1
Several security issues were fixed in libssh2.
> This month in security with Tony Anscombe – June 2026 edition
Three-day patching deadlines, exposed fuel-tank systems, scams costing billions of dollars, and social media bans for children all gave Tony plenty to unpack in June 2026
> Ubuntu 26.04 LTS libgd-perl Critical Command Execution Threat USN-8484-1
GD.pm could be made to run programs or overwrite files if it opened a specially crafted file.
> Ubuntu 26.04 HPLIP Severe Local Code Execution Vulnerabilities USN-8483-1
Several security issues were fixed in HPLIP.
> Update time: Apple releases security patches for iOS, MacOS Tahoe, Safari
A new Apple update fixes a multitude of browser and browser related vulnerabilities which have been public knowledge for a while
> GuardFall Exposes Open-Source AI Coding Agents to Decades-Old Shell Injection Risks
The safety check that is supposed to stop an AI coding agent from running a dangerous command can be walked straight past using a shell trick that has been public for decades. New research from Adversa AI, which is named the bypass GuardFall, found it works against ten of the eleven popular open-so...
> Apple Container : bien débuter avec les conteneurs macOS
Découvrez Apple Container, l'outil open source pour exécuter des conteneurs Linux sur macOS : installation, commandes, équivalent Compose et clients GUI. Le post Apple Container : bien débuter avec les conteneurs macOS a été publié sur IT-Connect.