[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (17 articles)

|

// AI-powered summary generated at 20:00

> Guarding AI memory
What happens when threat actors target what AI remembers? Microsoft breaks down the risks and the defenses. The post Guarding AI memory appeared first on Microsoft Security Blog.
> A new unpatchable flaw in Apple chips opens the door to an iPhone jailbreak 
European offensive cybersecurity company Paradigm Shift released details of a flaw and a technique to exploit it that opens the door for hackers to unlock and break into older iPhones.
> Texas Parks & Wildlife (TPWD) Data Breach impacts 3 Million People
Texas Parks and Wildlife Department (TPWD) breach exposed data of 3M people via a third-party license vendor, including sensitive personal information. The Texas Parks and Wildlife Department (TPWD) disclosed a data breach affecting around 3 million individuals after a third-party vendor used for hu...
> Anthropic says Claude may want to see your ID
Claude's chatbot may ask to verify your age and identity "in certain circumstances," such as with a passport or driver's license, according to a privacy policy change.
> ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack
Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack after unknown threat actors managed to tamper with the official release channels and push backdoor code. "Attackers compromised the vendor's build and distribution pipeline, injecting backdoor code into Pro plugi...
> How we found a bug in the hyper HTTP library
By rearchitecting the Images binding, we accidentally uncovered a bug that existed in the open-source hyper library across multiple major versions.
> Ubuntu 26.04 Google Guest Agent Important Denial Service Issues USN-8447-3
Several security issues were fixed in Google Guest Agent.
> Credential stuffing: what it is and how to protect your business accounts
Learn what credential stuffing is, why password reuse puts business accounts at risk, and how unique passwords help prevent attacks.
> Microsoft says Windows 11 26H2 is coming soon, details upgrade process
Microsoft has confirmed that Windows 11 version 26H2 will be the next feature update and that devices running Windows 11 24H2 and 25H2 will be able to upgrade using a small enablement package. [...]
> Microsoft fixes AutoGen Studio flaw that enabled code execution
A vulnerability chain dubbed AutoJack in Microsoft's AutoGen Studio interface for prototyping AI agents could let attackers manipulate an agent into executing arbitrary commands on its host system simply by visiting a malicious webpage. [...]
> AEPD - autorité espagnole
Le Réseau Ibéro-américain de Protection des Données (RIPD) a adopté un document de référence sur les garanties renforcées requises pour le traitement des neurodonnées dans les contextes non sanitaires.Ce document, impulsé par un groupe de travail coordonné par l'Agence Espagnole de Protection des Do...
> ICO - autorité britannique
Le Bureau du Commissaire à l'information (ICO) a publié une communication sur la tendance préoccupante de l'accès non autorisé aux dossiers médicaux par le personnel soignant.Suite à des incidents médiatisés à Nottingham et Southport, l'autorité a souligné une tendance inquiétante d'accès non autori...
> OpenAI Launches Full-Scale Effort to Patch Open-Source Bugs as It Takes on Anthropic’s Mythos
Amid concerns about AI models’ cybersecurity capabilities, OpenAI revealed an improved version of GPT-5.5-Cyber and its “Patch the Planet” initiative to fix open-source software bugs.
> Introducing Patch the Planet
What happens when you clear dozens of Trail of Bits engineers’ schedules, pair them with every open-source maintainer they can contact, and unleash the latest frontier models like GPT-5.5-Cyber on critical open-source targets? Thanks to our partnership with OpenAI and its Daybreak initiative, we can...
> How Hola Browser was weaponized to spread a Monero miner | Kaspersky official blog
A supply chain attack left some Windows users with a Monero crypto miner bundled right into their Hola Browser installation. Here is a breakdown of the incident.
> AWS Continuum offers devs help with securing code
AI coding agents are making it easier than ever to produce software. Ensuring that software is secure before deployment is another matter — one that AWS thinks AI should help with too. As enterprises adopt agentic development workflows, the volume of first-party code being...
> Fin de l’OTP SharePoint en 2026 : impacts pour votre DSI et alternatives pour le partage externe
L'OTP tel que vous le connaissez avec les partages externes SharePoint évolue pour s'appuyer sur Entra B2B : un changement important que vous devez anticiper. Le post Fin de l’OTP SharePoint en 2026 : impacts pour votre DSI et alternatives pour le partage externe a été publié sur IT-Connect.
> Klue breach exposed Salesforce CRM data through stolen OAuth tokens
An attacker broke into competitive-intelligence vendor Klue, stole OAuth tokens its customers use to connect to Salesforce and other platforms, and accessed data across multiple customer environments prompting the company to revoke customer OAuth tokens and disable affected in...
> Researchers Detail DifyTap Flaws in Dify That Could Expose AI Chats Across Tenants
Cybersecurity researchers have disclosed details of four vulnerabilities in Dify, an open-source agentic workflow platform with more than 146,000 GitHub stars, that could allow attackers to stealthily read artificial intelligence (AI) conversions from other customers' applications without requiring...
> 22nd June – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 22nd June, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Texas Parks and Wildlife Department has been affected by a third-party data breach involving its license system vendor. The incident exposed driver’s lic...