[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (1 articles)

|

// AI-powered summary generated at 04:00

> CRPx0 ransomware: what you need to know
CRPx0 is a cybercrime operation that started off operating a scam before pivoting into a fully-blown ransomware and cryptocurrency business. Read more in my article on the Fortra blog.
> The push to stop algorithms controlling social media feeds has begun
Australia is proposing a law that gives people a choice over what fills their feeds. It may not be long before other countries demand the same.
> 50% of CISOs see Mythos as a sign to exit the profession
CISOs already have it tough, but the straw that breaks the back of many IT security executives may be the rapidly advancing capabilities of frontier AI models, enterprise insistence on rapid and widespread AI experimentation, and the compounding risk responsibilities and perso...
> New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root
cPanel has patched a flaw that it says lets a single hosting account take control of an entire server. An authenticated account holder with mail-related privileges can create files of their choosing on the server through EmailTrack and, from there, run code as the root user. cPanel published the ad...
> SAP Patches Maximum Severity “Overpass” Flaw
Onapsis urges SAP customers to patch “Overpass” vulnerability, which has a CVSS score of 10.0
> Windows 11 KB5124008 : la mise à jour de septembre 2026 améliore la barre des tâches et corrige des bugs
KB5124008 et KB5122880 : les mises à jour Windows 11 de septembre 2026 sont là. Barre des tâches déplaçable, bugs d'août corrigés et une zero-day patchée. Le post Windows 11 KB5124008 : la mise à jour de septembre 2026 améliore la barre des tâches et corrige des bugs a été publié sur IT-Connect.
> Magento : la faille zero-day StyleSmuggler est corrigée, mais des boutiques sont déjà piratées
Exploitée depuis le 4 septembre 2026, la faille StyleSmuggler (CVE-2026-75650) permet de pirater Magento et Adobe Commerce. Un patch est disponible. Le post Magento : la faille zero-day StyleSmuggler est corrigée, mais des boutiques sont déjà piratées a été publié sur IT-Connect.
> Chaotic Eclipse Released ShieldCrash, A PoC For Microsoft Defender Zero-Day
The researcher Chaotic Eclipse released ShieldCrash, a PoC exploit for a Microsoft Defender Zero-Day vulnerability. Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Microsoft Defender. The researcher n...
> Google fixes yet another actively exploited Chrome zero-day (CVE-2026-87491)
Google has fixed 230 vulnerabilities in Chrome, including a zero-day flaw, CVE-2026-87491, with an in-the-wild exploit. “Google is aware that an exploit for CVE-2026-87491 exists in the wild,” the company said in a Tuesday security advisory. The fix has been shipped in Chrome 153.0.8010.36 and .37 f...
> Proxmox Backup Server : la sauvegarde locale est saine, mais oĂą est la copie hors ligne ?
Hors ligne versus hors site : comment composer une stratégie de sauvegarde fiable, conforme ANSSI et adaptée à Proxmox Backup Server ? Voici la réponse. Le post Proxmox Backup Server : la sauvegarde locale est saine, mais où est la copie hors ligne ? a été publié sur IT-Connect.
> F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans
Malware linked to break-ins at F5 BIG-IP Access Policy Manager appliances hides a PHP web shell in memory instead of in a file on disk, Sophos said in an analysis published on September 7. When Apache loads any of the three appliances' own PHP scripts, the malware adds the web shell to the copy hel...
> New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access
An anonymous security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldCrash" right after Microsoft rolled out its September 2026 Patch Tuesday security updates. [...]
> Microsoft’s Biggest Patch Tuesday: 974 CVEs, 2 Zero-Days and 20 Wormable Bugs
September 2026 Patch Tuesday fixes a record 974 CVEs including 2 exploited zero-days, 20 wormable bugs, and a critical Exchange RCE via Visio email. Microsoft’s September 2026 Patch Tuesday set a new record. Depending on how researchers count external and Chromium bugs, Microsoft fixed between 966 a...
> Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed
The security researcher known as Chaotic Eclipse has dropped a proof-of-concept (PoC) for yet another zero-day in Microsoft Defender. The vulnerability, codenamed ShieldCrash, is assessed to be a patch bypass for CVE-2026-69414 (CVSS score: 7.8), also called ShieldBreak, which the researcher report...
> Windows 10 KB5122878 : le point sur la mise Ă  jour ESU de septembre 2026
Mardi 8 septembre 2026, Microsoft a publié la KB5122878 pour Windows 10. Au-delà de patcher une faille zero-day, cette mise à jour corrige plusieurs bugs. Le post Windows 10 KB5122878 : le point sur la mise à jour ESU de septembre 2026 a été publié sur IT-Connect.
> Windows 11 va dire aux applications si vous ĂŞtes un enfant, un ado ou un adulte
Microsoft va ajouter des API d'âge à Windows 11 : les applications sauront si vous êtes enfant, ado ou adulte, sans accéder à votre date de naissance. Le post Windows 11 va dire aux applications si vous êtes un enfant, un ado ou un adulte a été publié sur IT-Connect.
> SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution
SAP has released security updates to address multiple vulnerabilities, including a maximum-severity flaw in SAP Extended Passport (EPP) Processing that could have a severe impact on the confidentiality, integrity, and availability of the application The vulnerability, tracked as CVE-2026-44756 (CVS...
> Google warns of new Chrome zero-day bug exploited in attacks
Google has patched 230 vulnerabilities on Tuesday, including another actively exploited Chrome zero-day bug, the seventh such vulnerability patched since the start of the year. [...]
> Patch Tuesday – Septembre 2026 : 973 failles corrigées, 2 zero-day exploitées et 20 failles wormables
Microsoft a corrigé 973 vulnérabilités avec le Patch Tuesday de septembre 2026, un record. Deux failles zero-day sont déjà exploitées, voici un récapitulatif. Le post Patch Tuesday – Septembre 2026 : 973 failles corrigées, 2 zero-day exploitées et 20 failles wormables a été publié sur IT-Connect.
> AI-Infra-Guard: Open-source security scanner for AI systems
Tencent’s Zhuque Lab built AI-Infra-Guard, an open-source security scanner for AI systems. It fingerprints running services such as Ollama, vLLM and ComfyUI and checks them against more than 1,600 known CVEs, inspects MCP servers and agent skills across 14 categories of risk, and runs jailbreak eval...