[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (1 articles)

|

// AI-powered summary generated at 04:00

> More than 100,000 fake stores are out to steal your card details
DoppelCart’s fake stores copy real retailers and steal shoppers’ card details and one-time bank confirmation codes.
> Researchers Build WeChat Zero-Click Worm Hijacking Phones via Calls
The hacking tool, built using a combination of AI models, is effective against Android and iOS devices
> Vol ou perte de smartphone professionnel : protéger les données
Smartphone professionnel perdu ou volé : le MDM aide à protéger les données, les accÚs et la flotte mobile.
> Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension
The critical, unauthenticated bugs allow attackers to bypass authentication and proxy a user’s browser traffic. The post Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension appeared first on SecurityWeek.
> Gigabud Uses Android App Cloning to Evade Fraud Detection
Gigabud clones banking apps into a work profile to break the link between malware alerts and fraud
> Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA
Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create "stolen keys" that grant illicit access to tools from model providers like Google, Anthropic, and others.  Information stealers like Lumma Stealer or Vidar are equipped to harvest a wide r...
> USN-8675-2: Perl vulnerabilities
USN-8675-1 fixed vulnerabilities in Perl. This update provides the corresponding fix for Perl on Ubuntu 26.04 LTS. Original advisory details: It was discovered that Perl incorrectly handled short source addresses in the Socket module. An attacker could possibly use this issue to trigger an out-...
> MFA's Weakest Link: Account Recovery Is the New Attack Path
MFA makes account takeover harder, but attackers are increasingly targeting the recovery processes used to reset passwords and authentication methods. Specops explains why stronger identity verification at the service desk is critical to preventing social engineering attacks from turning account rec...
> REACTIV : l’ANSSI obtient le pouvoir d’imposer des mesures d’urgence aux ministĂšres aprĂšs les fuites de donnĂ©es
AprĂšs les fuites DGFiP et Éducation nationale, l'ANSSI lance REACTIV et peut imposer des mesures immĂ©diates aux ministĂšres. Voici ce qu'il faut retenir. Le post REACTIV : l’ANSSI obtient le pouvoir d’imposer des mesures d’urgence aux ministĂšres aprĂšs les fuites de donnĂ©es a Ă©tĂ© publiĂ© sur IT-Connect...
> Akeyless adds real-time enforcement for AI agents in production
Akeyless has announced the general availability of Akeyless Agentic Runtime Authority, the real-time identity control layer for AI agent actions. It works on top of Akeyless SecretlessAI, a credential protection layer that keeps credentials out of AI agents and brokers access to enterprise systems....
> Google fixes the seventh actively exploited Chrome zero-day of 2026
Google patched 230 Chrome flaws, including an actively exploited V8 bug that could let attackers run arbitrary code through a crafted HTML page. Google released a Chrome update fixing 230 security vulnerabilities, including one already exploited in the wild tracked as CVE-2026-87491 (CVSS score of 8...
> ClickFix Moves into the Browser to Steal Cryptocurrency
ClickFix campaign uses browser-injected JavaScript and Google Sheets to steal cryptocurrency
> Orchid Security targets AI agent risk with drift detection and kill switches
Orchid Security has announced identity drift detection and application-level kill switches for AI agents. They can complete authorized objectives beyond their initial privilege level within seconds. AI agents do not need to “break” security controls or workflow guardrails. AI agents can find and use...
> Group of bipartisan lawmakers ask US government to ban several hack-for-hire firms
The three Indian companies are accused of using hackers to steal information used to sway litigation.
> How we rebuilt Cloudflare Workers’ module registry for Node.js compatibility
Workers now enables Node.js compatibility by default, supports applications up to 64 mebibytes, and adds a URL-based module registry with import.meta, lazy compilation, shared code caches, and clearer errors.
> FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
The remarks, to both CyberScoop and at the Billington CyberSecurity Summit, dovetail with the release of a new bureau cyber strategy. The post FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching appeared first on CyberScoop.
> Sequoia doubles down on Cymphony as AI agents create new enterprise security risks
Cymphony was valued at more than $100 million in a $25 million Series A co-led by Sequoia and SMBC Fin Atlas Beyond Fund.
> NHIs Now the Number One Corporate Entry Point for Hackers
SpyCloud claims non-human identities are the most likely route into the enterprise
> WeChat worm could pwn a friend before they even answered the call
Calif says AI helped turn a VoIP memory bug into cross-platform RCE before Tencent shut it down
> US Agencies Warn China Is Systematically Extracting Frontier AI Capabilities
Distillation is an ‘attack’ against an AI model designed to capture outputs, understand reasoning processes, and subsequently train a different model. The post US Agencies Warn China Is Systematically Extracting Frontier AI Capabilities appeared first on SecurityWeek.