[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (7 articles)

|

// AI-powered summary generated at 12:00

> Order-tracking app Shop abused to push callback phishing attacks
Threat actors are increasingly abusing Shop, the order-tracking app from Shopify, by adding fake purchase receipts in users' order histories to trick them into providing sensitive data or installing remote access software. [...]
> Debian PDNS Recursor Critical Denial Of Service Issues DSA-6369-1
Multiple vulnerabiliites have been discovered in PDNS Recursor, a resolving name server which could result in denial of service, cache poisoning or information disclosure. For the stable distribution (trixie), these problems have been fixed in version 5.2.11-0+deb13u1.
> Debian dnsdist Important Security Advisory DSA-6367-1 for Denial of Service
Multiple security vulnerabilities were discovered in the dnsdist DNS loadbalancer, which could result in denial of service, information disclosure or bypass of security rules. For the stable distribution (trixie), these problems have been fixed in version 1.9.15-0+deb13u1.
> Curl Fixes a 25-Year-Old Bug in Its Largest CVE Release Yet
Curl fixed 18 vulnerabilities, including a 25-year-old bug, with issues spanning auth bypass, memory safety, and host validation in libcurl. Curl maintainers addressed eighteen vulnerabilities with a single update, and one of them goes back 25 years. That’s not a typo, it really sat there since the...
> Debian pdns Significant Denial of Service Resolution DSA-6368-1
It was discovered that incorrect request handling in the internal web server of the PowerDNS DNS server could result in denial of service. For the stable distribution (trixie), this problem has been fixed in version 4.9.16-0+deb13u1. We recommend that you upgrade your pdns packages.
> DHS chief says president has met with potential CISA nominee; agency plans to hire 600
Once a new CISA director is in place, the agency will ramp up hiring efforts, Homeland Security Markwayne Mullin told lawmakers. The White House has not yet announced a nominee.
> Microsoft quietly extends free Windows 10 ESU support to October 2027
Microsoft has quietly extended its free Windows 10 Extended Security Updates (ESU) program for consumers by an additional year, allowing enrolled devices to continue receiving security updates until October 12, 2027. [...]
> Debian SOGo Critical XSS SQL Injection Issues DSA-6366-1
Multiple security vulnerabilities were discovered in the SOGo groupware server, which could result in cross-site scripting or SQL injection. For the stable distribution (trixie), these problems have been fixed in version 5.12.1-3+deb13u2. We recommend that you upgrade your sogo packages.
> Tietosuoja - autorité finlandaise
Le Bureau du délégué à la protection des données finlandais a émis un avertissement à l'encontre de l'Agence des services d'aide juridique et de tutelle pour avoir traité les données de crédit de ses employés sans base légale.L'agence avait contrôlé les données de crédit de 70 puis de 600 fonctionna...
> Debian libssh2 Critical Memory Disclosure DoS Exec Code DSA-6365-1
Multiple security vulnerabilities were discovered in libssh2, a client-side C library implementing the SSH2 protocol which could result in memory disclosure, denial of service or potentially the execution of arbitrary code. For the stable distribution (trixie), these problems have been fixed in
> DPA - autorité grecque
L'autorité grecque a prononcé une réprimande à l'encontre d'un organisme de crédit pour manquement au principe d'exactitude, en raison de retards dans la correction de données financières erronées, et lui a ordonné de revoir ses procédures de vérification.Faits et contexteL'autorité hellénique de pr...
> PIPC - autorité sud-coréenne
La Commission de Protection des Informations Personnelles (PIPC) sud-coréenne a émis des recommandations de correction à l’encontre de trois entreprises majeures du secteur des services funéraires suite à une inspection préventive sur le traitement des données personnelles.L'inspection, initiée en j...
> Beware of “Parcel Expert” job offers: They’re parcel mule scams
Most parcel mule scams start with fake job offers that trick victims into handling stolen goods.
> Médias et blogs
Le Conseil de l'Union européenne a abandonné la proposition de la Commission européenne visant à remplacer les bannières de cookies par un signal de consentement automatisé.La Commission avait initialement proposé d'introduire un nouvel article 88 ter au RGPD afin de substituer aux bannières de cook...
> BfDI - autorité allemande
Le Bundestag allemand a élu Moritz Hennemann comme nouveau Préposé fédéral à la protection des données et à la liberté d'information (BfDI).Il succède à Louisa Specht-Riemenschneider, qui se retire de ses fonctions pour des raisons de santé. Cette dernière continuera d'exercer ses fonctions jusqu'au...
> Beyond IOCs: AI-enabled threat intelligence
In this week’s newsletter, Martin considers how AI will help threat intelligence by creating an easily queryable data source of intelligence reports.
> ICO - autorité britannique
Le Bureau du Commissaire à l'Information (ICO) a exhorté les dirigeants du secteur de l'aide sociale à s'engager publiquement en faveur d'une amélioration de la création, de la gestion et de l'accès aux dossiers de soins.Cet appel, lancé le 25 juin 2026, s'inscrit dans la campagne "Mieux Gérer les D...
> Ubuntu 25.10 AMD Microcode Critical Data Exposure Vulnerability USN-8475-1
Several security issues were fixed in AMD Microcode.
> The FCC’s Spam Call Proposal Is Just a Data Collection Scheme
The Federal Communications Commission wants to require telecommunications providers to collect vast amounts of personal information from every person who wants a phone number in the name of combatting scam and spam calls. This plan will fail to combat the deluge of unwanted calls people in the Unite...
> Debian Chromium Critical Code Execution Denial of Service DSA-6364-1
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. For the stable distribution (trixie), these problems have been fixed in version 149.0.7827.196-1~deb13u1.