[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> AEPD - autorité espagnole
L'autorité espagnole sanctionne une société pour avoir fourni une adresse de courrier électronique non fonctionnelle, ce qui a empêché un client d'exercer son droit à l'effacement.Faits et contexteL'autorité espagnole de protection des données (AEPD) a aujourd'hui publié une décision de sanction à l...
> APD - autorité belge
L'Autorité belge de protection des données (APD) et l'Agence espagnole de protection des données (AEPD) ont publié conjointement un document de "Recommandations et bonnes pratiques dans le domaine des jeux vidéo" afin de promouvoir le respect du RGPD dans ce secteur.Ce guide a été élaboré pour répon...
> Spring 2026 SOC 1 and 2 reports are now available in OSCAL format
Amazon Web Services (AWS) is excited to release the Spring 2026 System and Organization Controls (SOC) 1 and 2 reports in machine-readable OSCAL format alongside the PDF version of the reports. The reports cover 188 services over the 12-month period from April 1, 2025 to March 31, 2026, giving custo...
> USN-8454-1: libheif vulnerabilities
Elhanan Haenel discovered that libheif incorrectly handled certain malformed HEIF sequence files. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-32738) Elhanan Haenel discovered that libheif incorrectly h...
> USN-8452-1: pbkdf2 vulnerability
Nikita Skovoroda discovered that pbkdf2 did not properly validate certain algorithm names. An attacker could possibly use this issue to generate predictable cryptographic keys, resulting in signature spoofing.
> USB worm spreads crypto-stealing malware via Windows shortcut files
Threat actors targeting cryptocurrency wallets have been distributing clipboard-stealing malware with self-spreading capabilities and using the Tor network to conceal communication. [...]
> USN-8453-1: Net::CIDR::Lite vulnerabilities
It was discovered that Net::CIDR::Lite incorrectly validated IP address and CIDR mask inputs. An attacker could possibly use this issue to bypass IP access control lists. (CVE-2026-45190) It was discovered that Net::CIDR::Lite incorrectly handled extraneous zero characters in CIDR mask values. An a...
> Cisco fixed a critical ISE vulnerability that lets attackers to gain root access
Cisco addressed CVE-2026-20181, a critical ISE vulnerability that lets authenticated admins execute commands and gain root access. Cisco addressed a critical command execution vulnerability, tracked as CVE-2026-20181 (CVSS score of 9.1), affecting Identity Services Engine (ISE) and ISE-PIC. The flaw...
> USN-8451-1: Vim vulnerabilities
Srinivas Piskala Ganesh Babu discovered that Vim incorrectly handled directory names when serializing browsed paths to the netrw history file. An attacker could possibly use this issue to execute arbitrary code. (CVE-2026-47162) It was discovered that Vim incorrectly handled step-definition pattern...
> Guide ClamAV : installer et configurer un antivirus sur Linux
Ce tutoriel explique comment installer et configurer l'antivirus ClamAV sur Linux (Debian, Ubuntu, Linux Mint) via la ligne de commande et l'outil ClamUI. Le post Guide ClamAV : installer et configurer un antivirus sur Linux a été publié sur IT-Connect.
> USN-8450-1: Tomcat vulnerabilities
It was discovered that Tomcat did not properly limit the size of WebDAV LOCK and PROPFIND request bodies. A remote attacker could possibly use this issue to cause Tomcat to consume excessive memory, resulting in a denial of service. (CVE-2026-41284) It was discovered that Tomcat incorrectly validat...
> World Cup 2026: watch out for these scams | Kaspersky official blog
The biggest World Cup 2026 scams to avoid.
> ThreatsDay Bulletin: Claude Chat Abuse, NastyC2 npm Packages, Device-Code Phishing + 25 More Stories
The internet did not break this week. It got used exactly as designed, which is worse. Searches were siphoned through shady browser add-ons. AI chat links turned into malware delivery paths. macOS attacks ran in memory and left almost nothing behind. Cloud agents looked like helpers until attackers...
> How software development’s speed obsession enabled TeamPCP’s chaos crusade
The threat group’s remarkable success targeting open-source software was inevitable and fueled by the industry’s decision to prioritize code shipping over security. The post How software development’s speed obsession enabled TeamPCP’s chaos crusade appeared first on CyberScoop.
> The Road to Post-Quantum Readiness Part 1 of 2: Understanding the Risk
Post-Quantum Cryptography is no longer a future-only concern. Standards are final, major providers have already deployed hybrid protection, and the real risk now is data captured today and decrypted later. Part 1 explains the fundamentals, the threat, and why organizations can no longer afford to wa...
> Accenture shells out $4.18B on three companies in big industrial cybersecurity push
The consulting giant’s majority stake in Dragos, along with the purchase runZero and NetRise, marks its first major push into operational technology software as AI-driven threats to critical infrastructure intensify. The post Accenture shells out $4.18B on three companies in big industrial cybersec...
> Fake GitHub Stars and AI Videos Mask a Crypto Clipper
A Rust crypto clipper hides behind fake GitHub stars and AI-narrated YouTube videos
> Google told researcher 'Nice catch!' Then denied bug bounty for flaw it still hasn't fixed
EXCLUSIVE 'Working as intended' for the win … again
> ICO Cautions Healthcare Worker After Princess of Wales Incident
Hospital insider escapes criminal prosecution after attempting to sell royal’s medical records
> Ubuntu 26.04 LTS ldns Important Spoofed DNS Response Risk USN-8449-1
ldns could be made to accept spoofed DNS responses.