[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (17 articles)

|

// AI-powered summary generated at 20:00

> GitHub Actions hardens checkout security to block ‘pwn request’ attacks
Stung by a surge in cyberattacks that have run amok in developer environments, GitHub has strengthened the security of actions/checkout to block ‘pwn request’ attacks that exploit insecure use of the pull_request_target workflow trigger to run an attacker’s code with the workf...
> OpenAI: Yoo-hoo, look over here, we do that security stuff too!
A plethora of pwn-prevention, including a 'Patch The Planet' pledge
> Ubuntu Linux-oracle 5.15 Important Privilege Escalation Threat USN-8462-1
Several security issues were fixed in the Linux kernel.
> Ubuntu 26.04 LTS Linux-Azure Critical Kernel Flaws USN-8461-1
Several security issues were fixed in the Linux kernel.
> Claude : Anthropic va vérifier l’âge et l’identité de ses utilisateurs dès le 8 juillet
À partir du 8 juillet 2026, Anthropic pourra demander aux utilisateurs de Claude une pièce d'identité : et si c'était pour donner un accès à Fable 5 ? Le post Claude : Anthropic va vérifier l’âge et l’identité de ses utilisateurs dès le 8 juillet a été publié sur IT-Connect.
> Ubuntu 22.04 Lowlatency High Socket Buffer Escalation USN-8388-2
Several security issues were fixed in the Linux kernel.
> WhatsApp phishing attack uses fake business docs to hack PCs
An ongoing malware campaign is targeting WhatsApp users in multiple countries with deceptive messages that push VBScript files, leading to remote system access. [...]
> Coupe du monde 2026 : une faille FIFA permettait de détourner les flux TV mondiaux
Une simple inscription comme agent de football ouvrait l'accès aux systèmes de production de la Coupe du monde 2026 : flux TV, scores, commentaires. Le post Coupe du monde 2026 : une faille FIFA permettait de détourner les flux TV mondiaux a été publié sur IT-Connect.
> Court rules SAVE database illegal, orders it dismantled
A judge said the administration’s database violates the Privacy Act, the Social Security Act and the Administrative Procedures Act. The post Court rules SAVE database illegal, orders it dismantled appeared first on CyberScoop.
> The Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data Exfiltration
Unit 42 research details how attackers could exploit global name uniqueness in bucket hijacking to redirect cloud data streams across major CSPs. The post The Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data Exfiltration appeared first on Unit 42.
> JaredFromSubway MEV bot hacked in $15 million crypto theft
The JaredFromSubway Ethereum MEV (Maximal Extractable Value) bot suffered a $15 million loss after an attacker manipulated the opportunity-detection logic by creating fake cryptocurrency trading opportunities. [...]
> Ubuntu Libxml2 Important DoS and Memory Leak Issues USN-8460-1
Several security issues were fixed in libxml2.
> FFmpeg fixes PixelSmash flaw in widely used video decoder
A newly disclosed FFmpeg flaw dubbed 'PixelSmash' could be exploited for remote code execution on Jellyfin servers under certain conditions, and can also trigger a denial-of-service  condition in applications like Kodi, Emby, Nextcloud, PhotoPrism, and OBS Studio. [...]
> WhatsApp Malware Campaign Hijacks Trust, Installs Legitimate Admin Tools
WhatsApp accounts were hijacked to spread fake debt notices that install remote access software, giving attackers control of victims’ PCs. Kaspersky published a technical analysis this week of an active malware campaign that spreads through WhatsApp messages and ends with a remote management tool si...
> Cloudflare teams up with big browsers to help websites tell bots from people
Makers of Chrome, Edge, Firefox back bot-fraud defense called Private Access Control Tokens
> FortiBleed campaign used custom FortiGate sniffer to steal credentials
Security firm SOCRadar says the large-scale FortiBleed campaign targeting Fortinet FortiGate devices used custom sniffers to harvest authentication secrets from compromised firewalls and steal credentials. [...]
> Trump administration to order agencies to speed up post-quantum migration, boost industry
Both EOs are expected to be signed as soon as Monday per an industry source with knowledge of timing. The White House has a signing ceremony scheduled this afternoon.  The post Trump administration to order agencies to speed up post-quantum migration, boost industry appeared first on CyberScoop.
> Security shops among the 'hundreds' of Klue hack victims
As yet another extortion crew Icarus exploits Salesforce-linked integrations
> Debian FFmpeg Critical Denial of Service Code Execution Vuln DSA-6361-1
Several vulnerabilities have been discovered in the FFmpeg multimedia framework, which could result in denial of service or potentially the execution of arbitrary code if malformed files/streams are processed. For the stable distribution (trixie), these problems have been fixed in version 7:7.1.5-0+...
> Tata Electronics, a major tech supplier to Apple and Tesla, confirms data breach
The incident comes as Tata Electronics expands its role in global technology supply chains.