L'autorité espagnole sanctionne une société pour avoir fourni une adresse de courrier électronique non fonctionnelle, ce qui a empêché un client d'exercer son droit à l'effacement.Faits et contexteL'autorité espagnole de protection des données (AEPD) a aujourd'hui publié une décision de sanction à l...
L'Autorité belge de protection des données (APD) et l'Agence espagnole de protection des données (AEPD) ont publié conjointement un document de "Recommandations et bonnes pratiques dans le domaine des jeux vidéo" afin de promouvoir le respect du RGPD dans ce secteur.Ce guide a été élaboré pour répon...
Amazon Web Services (AWS) is excited to release the Spring 2026 System and Organization Controls (SOC) 1 and 2 reports in machine-readable OSCAL format alongside the PDF version of the reports. The reports cover 188 services over the 12-month period from April 1, 2025 to March 31, 2026, giving custo...
Elhanan Haenel discovered that libheif incorrectly handled certain
malformed HEIF sequence files. An attacker could possibly use this
issue to cause a denial of service. This issue only affected Ubuntu 25.10
and Ubuntu 26.04 LTS. (CVE-2026-32738)
Elhanan Haenel discovered that libheif incorrectly h...
Nikita Skovoroda discovered that pbkdf2 did not properly validate
certain algorithm names. An attacker could possibly use this issue to
generate predictable cryptographic keys, resulting in signature spoofing.
Threat actors targeting cryptocurrency wallets have been distributing clipboard-stealing malware with self-spreading capabilities and using the Tor network to conceal communication. [...]
It was discovered that Net::CIDR::Lite incorrectly validated IP address and
CIDR mask inputs. An attacker could possibly use this issue to bypass IP
access control lists. (CVE-2026-45190)
It was discovered that Net::CIDR::Lite incorrectly handled extraneous zero
characters in CIDR mask values. An a...
Cisco addressed CVE-2026-20181, a critical ISE vulnerability that lets authenticated admins execute commands and gain root access. Cisco addressed a critical command execution vulnerability, tracked as CVE-2026-20181 (CVSS score of 9.1), affecting Identity Services Engine (ISE) and ISE-PIC. The flaw...
Srinivas Piskala Ganesh Babu discovered that Vim incorrectly handled
directory names when serializing browsed paths to the netrw history file.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2026-47162)
It was discovered that Vim incorrectly handled step-definition pattern...
Ce tutoriel explique comment installer et configurer l'antivirus ClamAV sur Linux (Debian, Ubuntu, Linux Mint) via la ligne de commande et l'outil ClamUI.
Le post Guide ClamAV : installer et configurer un antivirus sur Linux a été publié sur IT-Connect.
It was discovered that Tomcat did not properly limit the size of
WebDAV LOCK and PROPFIND request bodies. A remote attacker could
possibly use this issue to cause Tomcat to consume excessive memory,
resulting in a denial of service. (CVE-2026-41284)
It was discovered that Tomcat incorrectly validat...
The biggest World Cup 2026 scams to avoid.
The internet did not break this week. It got used exactly as designed, which is worse.
Searches were siphoned through shady browser add-ons. AI chat links turned into malware delivery paths. macOS attacks ran in memory and left almost nothing behind. Cloud agents looked like helpers until attackers...
The threat group’s remarkable success targeting open-source software was inevitable and fueled by the industry’s decision to prioritize code shipping over security.
The post How software development’s speed obsession enabled TeamPCP’s chaos crusade appeared first on CyberScoop.
Post-Quantum Cryptography is no longer a future-only concern. Standards are final, major providers have already deployed hybrid protection, and the real risk now is data captured today and decrypted later. Part 1 explains the fundamentals, the threat, and why organizations can no longer afford to wa...
The consulting giant’s majority stake in Dragos, along with the purchase runZero and NetRise, marks its first major push into operational technology software as AI-driven threats to critical infrastructure intensify.
The post Accenture shells out $4.18B on three companies in big industrial cybersec...
A Rust crypto clipper hides behind fake GitHub stars and AI-narrated YouTube videos
EXCLUSIVE 'Working as intended' for the win … again
Hospital insider escapes criminal prosecution after attempting to sell royal’s medical records
ldns could be made to accept spoofed DNS responses.