[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (1 articles)

|

// AI-powered summary generated at 08:00

> CVE-2026-58058 Nmap - Integer Underflow in IPv6 Extension Header Parsing
Information published.
> CVE-2026-58055 nghttp2 nghttpx - HTTP Request/Response Smuggling via Upgrade Request with Content-Length
Information published.
> Do excellent vulnerability reports
Over the years, we have received, read and handled way over one thousand vulnerability reports filed against curl. We have seen most kinds. It is time for me to try to help future reporters by providing a short guide on how to submit a truly excellent vulnerability report to an Open Source project....
> CVE-2026-52910 bpf: Free reuseport cBPF prog after RCU grace period.
Information published.
> CVE-2026-52908 RDMA: During rereg_mr ensure that REREG_ACCESS is compatible
Information published.
> OpenAI Unveils GPT-5.6 Sol as Its Most Advanced Cybersecurity AI
The company says Sol matches competing systems like Mythos Preview while using only a third of the output tokens. The post OpenAI Unveils GPT-5.6 Sol as Its Most Advanced Cybersecurity AI appeared first on SecurityWeek.
> CVE-2026-58050 libssh2 - Integer Overflow in publickey Subsystem Attribute Allocation
Information published.
> CVE-2026-52909 ip6_vti: set netns_immutable on the fallback device.
Information published.
> Adblock for YouTube : 11 millions d’installations et une grave faille à corriger !
Adblock for YouTube, bloqueur de pubs aux 11 millions d'installations, embarque une capacité d'injection de code activable à distance. Un correctif attendu. Le post Adblock for YouTube : 11 millions d’installations et une grave faille à corriger ! a été publié sur IT-Connect.
> Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw
A public proof-of-concept is now out for CVE-2026-55200, a critical flaw in libssh2 that lets a malicious or compromised SSH server trigger memory corruption on a connecting client, with possible code execution. No credentials, no user interaction. The bug affects every release up to and including 1...
> A week in security (June 22 – June 28)
A list of topics we covered in the week of June 22 to June 28 of 2026
> DirtyClone : la faille Linux qui donne un accès root en silence
DirtyClone (CVE-2026-43503), nouvelle faille du noyau Linux, permet à un utilisateur local de devenir root sur Debian, Ubuntu et Fedora. Comment se protéger. Le post DirtyClone : la faille Linux qui donne un accès root en silence a été publié sur IT-Connect.
> Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer
Cybersecurity researchers have uncovered two hijacked npm packages and a cluster of Go packages that are designed to deploy a Python-based information stealer on compromised Windows, Linux, and macOS hosts. "This attack avoids the most common npm execution paths through lifecycle scripts, perhaps i...
> DarkMoon: Open-source AI pentesting platform
Penetration testing has long run on expert time, with specialists spending days probing a network or web application by hand. Manual engagements stretch across weeks, expert consultants run into thousands of dollars a day, and results vary with the tester. Automation promises to narrow those gaps. A...
> Sycophantic chatbots and the harms that build over many chats
People use AI chatbots for company, advice, and emotional support, and these systems answer in ways meant to hold their attention. Researchers describe the resulting risks as affective safety, a class of harm that exists because humans are emotional beings and because the systems engage directly wit...
> Falcon Cloud Security June 2026 Release: Updates for Azure and Google Cloud
> Companies keep bolting AI onto their products, and the security bill is coming due
Companies keep bolting AI and LLM features onto their products, and the security results are starting to show a pattern. The vulnerabilities those features create get rated high risk far more often than anything else, and they get fixed slower than anything else. The figures come from Cobalt’s AI an...
> Most teams accept higher risk for faster AI database work
Database professionals are using AI for everyday work like writing queries, building schemas, and reviewing code, and a growing share rely on autonomous tools that act on the database itself. The use of AI in database management has almost tripled in a year, climbing from 15% to 44% of organizations...
> ISC Stormcast For Monday, June 29th, 2026 https://isc.sans.edu/podcastdetail/9986, (Mon, Jun 29th)
> Salida Union School District
Le Salida School District, situé dans le Colorado, a subi une cyberattaque qui a forcé la mise hors ligne de son réseau le 29 juin. L'attaque a endommagé des fichiers stockés localement et perturbé les opérations administratives, bien que les systèmes basés sur le cloud soient restés opérationnels....