[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (7 articles)

|

// AI-powered summary generated at 12:00

> Oracle Linux 9 Unbound Significant Security Notice ELSA-2026-24369
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
> What do Ports Hear When Nobody's Listening? An Assessment of Automated Cybercrime [Guest Diary], (Wed, Jun 24th)
[This is a Guest Diary by Nicole Phillips, an ISC intern as part of the SANS.edu BACS program]
> Ukrposhta
The national postal operator, Ukrposhta, reported that its mobile application experienced temporary disruptions following a cyberattack on its IT systems. The attack, which occurred during the night of June 24th/25th, caused instability and operational failures in the digital services. Ukrposhta con...
> Govern privileged workload boundaries with Red Hat OpenShift, Ansible Automation Platform, and Identity Management
Platform engineering, security architecture, and operations teams are being asked to support 2 realities at once: modern application platforms such as Red Hat OpenShift, and long-lived Red Hat Enterprise Linux (RHEL) fleets that still run critical automation. These parallel systems introduce risk, e...
> Cardiology Associates of Port Huron (CAPH)
Cardiology Associates of Port Huron (CAPH), un cabinet médical du Michigan, a été potentiellement victime d'une violation de données par le groupe Orova. Orova prétend avoir acquis 496 Go de données, incluant des informations d'identification personnelles et des données de santé protégées (PHI) de 2...
> Atlas Elektronik (TKMS)
Atlas Elektronik, une filiale de TKMS (ThyssenKrupp Marine Systems), un géant de la défense allemand, a été victime d'une cyberattaque. L'attaque a ciblé la succursale nord-américaine de l'entreprise, qui gère des projets pour l'armée américaine. Bien que l'entreprise ait confirmé que les données mi...
> Multiples vulnérabilités dans CPython (25 juin 2026)
De multiples vulnérabilités ont été découvertes dans CPython. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service à distance, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.
> Multiples vulnérabilités dans GitLab (25 juin 2026)
De multiples vulnérabilités ont été découvertes dans GitLab. Certaines d'entre elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données, une falsification de requêtes côté serveur (SSRF) et une injection de code indirecte à distance (XSS).
> Latvijas Valsts meĹľi (LVM)
Suite à un cyberincident, Latvijas Valsts meži (LVM) a désactivé et rendus inaccessibles ses systèmes informatiques externes (LVM GEO, le service cartographique et l’application de chasse « Mednis ») ainsi que plusieurs systèmes internes assurant les échanges avec ses fournisseurs et clients, pour d...
> Multiples vulnérabilités dans Google Chrome (25 juin 2026)
De multiples vulnérabilités ont été découvertes dans Google Chrome. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.
> Multiples vulnérabilités dans Microsoft Azure Linux (25 juin 2026)
De multiples vulnérabilités ont été découvertes dans Microsoft Azure Linux. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.
> Google releases new privacy controls for activity history, personalization
Google is rolling out new privacy controls for Search services and Google Play, giving you more control over saved history and personalized recommendations. [...]
> Smashing Security podcast #473: How a hacker could have Rickrolled the entire World Cup
A polite caller from your bank says there is a problem with your account. Don't worry - they'll send someone round to help. They'll even take your cards away to keep them safe. The scam has run rampant, until Dutch police plastered blurred photos of 100 suspects across billboards, supermarkets, and...
> Akaolife, l’intrusion qui menace France Travail ?
Intrusion revendiquée chez Akaolife : données RH, santé et France Travail au cœur d’un risque cyber majeur ?
> The hits keep on coming for Cisco vulnerabilities
CVE-2026-20230 under exploitation, while an earlier SD-WAN 0-day looks even worse than we thought
> Be on the lookout for Mistic, a new backdoor used by ransomware broker
Researchers have identified a new backdoor program that has been used in enterprise intrusions since April and appears to be linked to an initial access broker that sells network footholds to ransomware gangs. Dubbed Mistic by researchers from Symantec, the malware program...
> DraftKings hacker 'Snoopy' sentenced to 18 months in prison
A 21-year-old using the alias "Snoopy" was sentenced to 18 months in prison for his role in hacking DraftKings accounts in the November 2022 cyberattack. [...]
> a CVE dispute
A few years years ago the curl project signed up and became a CNA. This means that we are masters of and can allocate our own CVE identifiers. For any security problems within our territory, it is we who decides if the issue should get a CVE or not. No more bogus CVEs. 57 CVEs … Continue reading a C...
> Mandiant reveals how Cisco SD-WAN zero-day attacks gained root access
New details have been revealed on how hackers exploited a Cisco Catalyst SD-WAN vulnerability tracked as CVE-2026-20245 in zero-day attacks to create rogue root accounts on targeted devices. [...]
> New website names and shames companies that still don’t offer passkeys to users
According to a new site, 24% of the most popular websites in the world don't offer support for passkeys, which are considered the most secure way to log in to apps and services.