[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> May Trucking Company
May Trucking Company suffered a data breach that may have exposed customers' first and last names and Social Security numbers. The breach occurred when unauthorized individuals acquired certain files within the company's network. A cyberattack was claimed by Embargo on June 30.
> HĂŽpital de l'UniversitĂ© de Dokuz EylĂŒl (DEÜ)
L'HĂŽpital de l'UniversitĂ© de Dokuz EylĂŒl (DEÜ) a connu une double crise. Une cyberattaque a provoquĂ© la panne de son infrastructure numĂ©rique, affectant le systĂšme d'enregistrement des patients. SimultanĂ©ment, des perturbations de service ont Ă©tĂ© signalĂ©es en raison d'une action syndicale contre la...
> QUERY with curl
RFC 10008 is brand new a specification detailing the new HTTP method called QUERY: This specification defines the QUERY method for HTTP. A QUERY requests that the request target process the enclosed content in a safe and idempotent manner and then respond with the result of that processing. This is...
> Signal’s Meredith Whittaker wants you to remember that AI chatbots ‘are not your friends’
"These are not your friends. These are not conscious beings. These are not sentient interlocutors.”
> Inside GentleKiller: The EDR-Killer Powering The Gentlemen
The Gentlemen equips affiliates with a centralized EDR-killer suite, rapidly weaponizing BYOVD exploits to disable security tools before ransomware attacks. ESET published a detailed breakdown of The Gentlemen‘s technical infrastructure on June 18, the result of months of incident-level investigatio...
> New Prinz Eugen ransomware prioritizes recent files for encryption
A new ransomware operation named 'Prinz Eugen' prioritizes recently modified files for encryption and leaves no ransom note on the system. [...]
> Why Amazon hates 'human-in-the-loop' AI governance
VP Eric Brandwine explains people aren't all that great, actually
> Microsoft links Mastra AI supply chain attack to North Korean hackers
Microsoft has attributed a recent Mastra AI supply chain attack that compromised more than 140 npm packages to the North Korean hacking group Sapphire Sleet, also known as BlueNoroff. [...]
> Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys
Threat actors are exploiting a recently patched security flaw impacting Gravity SMTP, a WordPress plugin that's installed on about 100,000 sites. The vulnerability, tracked as CVE-2026-4020 (CVSS score: 5.3), is a medium-severity information disclosure flaw that can allow unauthenticated attackers...
> French President Urges US to Share Cutting-Edge AI and Democracies to Cooperate on Regulation
French President Emmanuel Macron urged the world’s wealthy democracies to work together on regulating advanced AI systems. The post French President Urges US to Share Cutting-Edge AI and Democracies to Cooperate on Regulation appeared first on SecurityWeek.
> Hackers Claim to Leak Stolen Madison Square Garden Data
Plus: Gay bars in San Francisco using face scanners, France quits Palantir, Apple plans to change its private email and more.
> CVE-2026-46331 net/sched: fix pedit partial COW leading to page cache corruption
Information published.
> CVE-2025-5791 Users: `root` appended to group listings
Information published.
> FortiBleed Exposes Global Credential-Spraying Operation
FortiBleed exposed a massive campaign that made billions of login attempts against Fortinet VPNs, compromising organizations worldwide. FortiBleed wasn’t a targeted hack. It was a factory. A multi-operator crew ran an industrial-scale attack against Fortinet FortiGate SSL VPN devices worldwide, and...
> CVE-2025-4574 Crossbeam-channel: crossbeam-channel vulnerable to double free on drop
Information published.
> CISA Warns of Active Exploitation Following FortiBleed Leak
FortiBleed exposed credentials for 74,000 Fortinet devices, with attackers actively exploiting the leak to target systems worldwide. On June 18, CISA issued an emergency alert after reports surfaced that credentials for approximately 74,000 Fortinet firewalls and VPN gateways had been leaked in what...
> JCPenney - 368,418 breached accounts
In June 2026, retailer JCPenney and associated brands were targeted in a ShinyHunters "pay or leak" extortion campaign. Data allegedly obtained from JCPenney through the exploitation of a critical zero-day vulnerability in Oracle PeopleSoft was later published publicly. The exposed records indicated...
> Threat Brief: Mitigating Large-Scale Credential Attacks
We provide guidance for preparing for and mitigating large-scale credential attacks, focusing on recent campaigns targeting security vendors' devices. The post Threat Brief: Mitigating Large-Scale Credential Attacks appeared first on Unit 42.
> Todd, Hamaker & Johnson, LLP
Un cabinet comptable de Lufkin, Todd, Hamaker & Johnson, LLP, a été listé par le groupe de ransomware Akira. Ce groupe prétend avoir volé environ 40 gigaoctets de données sensibles de clients et d'employés, y compris des dossiers financiers, des contrats, des numéros de sécurité sociale, des permis...
> Defesa Civil Nacional
A massive cyberattack compromised Brazil's national emergency alert system, Defesa Civil Alerta, causing millions of citizens across multiple states to receive false, extreme emergency notifications. The alerts, which were broadcast via Cell Broadcast technology, contained alarming messages, includi...