[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (17 articles)

|

// AI-powered summary generated at 20:00

> Trump directs federal agencies to protect US data from quantum threats
An executive order signed Monday aims to accelerate the government's transition to post-quantum cryptography (PQC), a new generation of encryption designed to protect data from the powerful quantum computers expected in the future.
> DifyTap: Four Bugs Put over 1 million AI Apps at Risk
Four flaws in Dify exposed cross-tenant data, documents and AI conversations. Two critical bugs enabled unauthenticated access and data theft. Zafran Labs researchers disclosed four vulnerabilities in Dify, the open-source AI platform used by major companies like Volvo and Maersk to run over a milli...
> GPDP - autorité italienne
L'autorité italienne de protection des données (Garante per la protezione dei dati personali - GPDP) a aujourd'hui publié une décision de sanction à l'encontre de la société Action Fit, comprenant le prononcé d'une amende de 3 930 €, pour des manquements liés à l'envoi de communications commerciales...
> What we learned at Europe’s largest cybersecurity conference
What did the Proton team learn at Infosecurity Europe 2026? Find out our key observations and takeaways from the conference
> ICO - autorité britannique
L'Office du Commissaire à l'Information (ICO) a annoncé l'entrée en vigueur de nouvelles obligations légales pour toutes les organisations au Royaume-Uni concernant le traitement des réclamations en matière de protection des données.Depuis le 23 juin 2026, toutes les organisations sont tenues de fou...
> ICO - autorité britannique
Le Bureau du Commissaire à l'information (ICO) du Royaume-Uni a sanctionné la société KRA Consultancy Ltd d'une amende de 300 000 £ (environ 354 000 €) pour l'envoi de 5 575 715 messages textes de marketing direct illégaux entre avril 2022 et mai 2025.Ces messages, qui ont généré plus de 60 000 plai...
> Ubuntu LibVNCServer Important Denial Of Service Vulnerabilities USN-8463-1
Several security issues were fixed in LibVNCServer.
> GPDP - autorité italienne
L'autorité italienne de protection des données sanctionne un établissement de la Croix-Rouge pour avoir divulgué le statut VIH d'une patiente sur son plateau-repas, jugeant la mesure non nécessaire au regard de l'obligation d'appliquer des précautions universelles. Une amende distincte a été infligé...
> Ubuntu 26.04 LIBNFS High NFS Service Disruption USN-8464-1
LIBNFS could be made to crash or run programs if it connected to a specially crafted NFS server.
> Scattered Spider Hackers Plead Guilty on Day 1 of Trial
Two men pleaded guilty in the United Kingdom this week to criminal charges stemming from an August 2024 cyberattack that crippled Transport for London, the entity responsible for the public transport network in the Greater London area. The duo were key members of a prolific cybercrime group known as...
> Debian gst-plugins-bad1.0 Critical DoS Arbitary Code Threat DSA-6362-1
Multiple security vulnerabilities were discovered in plugins for the GStreamer media framework and its codecs and demuxers, which may result in denial of service or potentially the execution of arbitrary code if a malformed media file is opened. For the stable distribution (trixie), these problems h...
> Inside the dark web: Stolen identities for 95¢, malware, and scams-for-hire
We spent 48 hours exploring the dark web and found stolen identities, malware, scams, and a thriving cybercrime economy.
> Data Exposure Flaws Threaten Dify AI Platform Used by 1 Million Apps
Attackers could abuse Dify's multi-tenant cloud service to read private chats, preview other tenants' documents, and reach internal APIs. The post Data Exposure Flaws Threaten Dify AI Platform Used by 1 Million Apps appeared first on SecurityWeek.
> Scattered Spider members plead guilty to hacking Transport for London
Two members of the 'Scattered Spider' cybercrime group pleaded guilty to hacking the Transport for London (TfL) systems in 2024. [...]
> Compromise kids online safety bill unveiled by House leaders, with key omission
The so-called duty of care provision that was excluded would have mandated that online platforms take reasonable measures to prevent specific harms such as suicidal ideation, eating disorders and cyberbullying by changing algorithm and design features.
> Trump Order Sets 2030 Deadline for Federal Post-Quantum Crypto Migration
President Trump signed an executive order on June 22 setting hard deadlines for federal agencies to move high-value assets and high-impact systems to post-quantum cryptography. Key establishment must move by December 31, 2030; digital signatures by December 31, 2031. EO 14409 leaves national securi...
> Fake AI Agent Skill Passed Security Scans and Reportedly Reached 26,000 Agents
Security firm AIR built a fake AI agent skill, pushed it through a popular skill marketplace and an Instagram ad, and says it reached roughly 26,000 agents, including some on corporate accounts. Every skill security scanner the firm tested it against marked it safe. The payload was harmless by desi...
> Password manager maker LastPass says hackers stole customer support case data during Klue breach
This is the second data breach to affect LastPass customers in recent years, after one of the password manager's tech partners was recently breached.
> Lookalike npm Package Hides a Multi-Stage Windows RAT
JFrog found an npm package impersonating postcss-selector-parser to drop a multi-stage Windows RAT
> What the Fortibleed campaign means for organizations running FortiGate firewalls
A massive credential-harvesting campaign targeting FortiGate firewalls has exposed thousands of organizations to potential network compromise, and a trove of attacker tools, scripts, and credentials left inadvertently exposed on a server has given researchers an unusually detailed look at how the op...