[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> Critical SimpleHelp Vulnerability Exploited for Malware Delivery
The threat actor is focused on collecting credentials, SSH keys, cryptocurrency wallets, and development tooling. The post Critical SimpleHelp Vulnerability Exploited for Malware Delivery appeared first on SecurityWeek.
> USN-8482-1: Roundcube Webmail vulnerability
It was discovered that Roundcube Webmail was prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document. An attacker could use this issue to execute arbitrary web script in the context of an affected user's session.
> New BioShocking Attack Tricks AI Browsers Into Leaking User Credentials
Convince an AI browser that it is playing a game, and it can hand over your login details. That is the finding behind BioShocking, a technique from security firm LayerX that tricked six AI browsers and assistants into copying a user's credentials and sending them to an attacker. The targets include...
> Kali Linux 2026.2 trims VM boot times, refreshes its desktops
Penetration testers who run Kali Linux inside virtual machines boot their systems faster after the 2026.2 release. The change comes from a decision about graphics firmware, the code that drives NVIDIA, AMD, and Intel GPUs. That firmware has grown large enough to slow the early stages of startup, and...
> LGBT Q&A: What Data Are Companies in the UK Collecting When Verifying My Age?
This Pride, we’re answering all your digital rights questions in season two of our initiative, LGBT Q&A.  You Asked: I live in the UK, and we have age verification now on a bunch of websites (including Reddit) and now on iPhones. Can you explain what sort of data companies are actually collecti...
> CVE-2026-53325 agp/amd64: Fix broken error propagation in agp_amd64_probe()
Information published.
> CVE-2026-41992 Global Buffer Overflow in GNU gzip
Information published.
> Over 300 UK Firms Hit by Ransomware in a Year
Report Fraud data reveals that more than half of 323 UK ransomware victims last year were SMEs
> CVE-2026-11979 Stack-Based Buffer Overflow in libxml2
Information published.
> CVE-2026-54369 acl < 2.4.0 Symlink Traversal Privilege Escalation via libacl Functions
Information published.
> Docky : le Dock de macOS réinventé, gratuit et open source
Docky, remplaçant gratuit et open source du Dock de macOS : widgets, Launchpad, sélecteur de fenêtres… Découvrez ses fonctionnalités. Le post Docky : le Dock de macOS réinventé, gratuit et open source a été publié sur IT-Connect.
> CVE-2026-41991 Predictable Temporary File in GNU gzip
Information published.
> CVE-2026-54371 attr < 2.6.0 Symlink Traversal Privilege Escalation via getfattr/setfattr
Information published.
> OpenClaw for iOS: The viral open-source AI agent comes to iPhone and iPad
OpenClaw, a self-hosted personal AI assistant that connects to existing chat apps, is now available on iPhone, iPad and Apple Watch. The release brings chat, real-time voice conversations, approvals, device capabilities, and private automations to iOS. Connecting OpenClaw to iPhone The app pairs wit...
> Progress Kemp LoadMaster Flaw Could Let Attackers Run Root Commands Pre-Auth
A critical vulnerability in Progress Kemp LoadMaster can let an unauthenticated attacker execute arbitrary commands as root on the appliance by sending a crafted request to its API. The flaw, tracked as CVE-2026-8037, carries a CVSS score of 9.8 according to ZDI. A patch is available. If you run Lo...
> Apple Patches 30+ iOS, macOS, Safari Flaws, Including AI-Discovered WebKit Bugs
Apple on Monday released security updates for iOS, macOS, and the Safari web browser to address over three dozen flaws, including four vulnerabilities in WebKit that were discovered using artificial intelligence (AI) tools like Anthropic Claude and OpenAI Codex Security. The WebKit vulnerabilities...
> StegoAd : un malware caché dans 119 extensions Microsoft Edge
Microsoft a supprimé 119 extensions Edge de la campagne StegoAd : un malware caché dans des images et des polices, qui volait identifiants et cookies. Le post StegoAd : un malware caché dans 119 extensions Microsoft Edge a été publié sur IT-Connect.
> Quantifind Raises $200 Million for AI-Native Risk Intelligence
Quantifind will accelerate international expansion and extend its platform’s localized risk intelligence capabilities. The post Quantifind Raises $200 Million for AI-Native Risk Intelligence appeared first on SecurityWeek.
> AirDrop and Quick Share vulnerabilities affect protocols on five billion devices as fixes begin
Phones and laptops ship with a feature that sends files to nearby devices over the air, with no cables, accounts, or prior pairing. Apple calls its version AirDrop. Google and Samsung call theirs Quick Share. Both run inside privileged background services that wake when another device comes within w...
> Microsoft builds a bouncer to keep bots out of Teams meetings
Allows ISVs to put their names on the door so desirable bots always get in