L'autorité italienne de protection des données (Garante) sanctionne l'Agence pour l'Italie numérique (AgID) d'une amende de 55 000 € pour ne pas avoir informé les professionnels du transfert automatique et de la publication de leur domicile numérique professionnel dans un nouvel annuaire public, acc...
Microsoft has formally disclosed that it's working to release a patch to address a Defender zero-day codenamed RoguePlanet.
The vulnerability has now been assigned the CVE identifier CVE-2026-50656 (CVSS score: 7.8), with the tech giant describing it as a privilege escalation flaw.
"Microsoft is a...
L'autorité italienne de protection des données a sanctionné la compagnie aérienne Emirates pour des manquements liés à la transparence et à la durée de conservation des données de santé collectées via son formulaire médical, tout en reconnaissant la légitimité de cette collecte au nom de la sécurité...
It was discovered that atril, the MATE document viewer, is prone to a command injection vulnerability if a specially crafted PDF file is opened. For the stable distribution (trixie), this problem has been fixed in version 1.26.2-4+deb13u1.
L'autorité italienne de protection des données a sanctionné une entreprise de santé publique pour un suivi par géolocalisation jugé excessif de ses véhicules de service, et pour l'utilisation illicite des données collectées dans le cadre d'une procédure disciplinaire.Faits et contexteL'autorité ital...
L'autorité espagnole de protection des données (AEPD) a sanctionné Vodafone España à hauteur de 1 050 000 € pour des manquements graves aux principes de licéité et de sécurité, ayant permis l'ouverture d'une ligne et la communication d'une facture à un tiers non autorisé.Faits et contexteL'autorité...
On March 30th, 2026, we publicly disclosed a Sensitive Information Exposure vulnerability in Gravity SMTP, a WordPress plugin with an estimated 100,000 active installations. This vulnerability can be leveraged by unauthenticated attackers to retrieve detailed system configuration data and, criticall...
La Commission Nationale de l'Informatique et des Libertés (CNIL) a détaillé les règles applicables aux dispositifs de contrôle d'accès aux locaux et de suivi des horaires de travail.L'employeur peut mettre en place des outils de contrôle individuel pour sécuriser l'accès aux bâtiments et aux zones r...
Why are you even reading this?! Rotate your passwords!!
Effective cloud document management can save your business hours every week. Learn how to build a system that keeps your team productive.
Sanctions compliance in crypto isn’t just about knowing who’s on a list today. It’s about understanding the full arc of…
The post Seeing the Full Picture: Why Pre- and Post-Designation Exposure Changes Everything in Sanctions Screening appeared first on Chainalysis.
See how Microsoft unifies identity and security signals to help teams prevent, detect, and respond to AI-accelerated attacks faster.
The post AI is accelerating cyberattacks—here’s how to stay ahead appeared first on Microsoft Security Blog.
Several security issues were fixed in Go Cryptography.
As Kyiv takes steps toward formal accession to the EU, the bloc is integrating Ukraine with its pool of pre-approved cybersecurity incident response companies.
A French-speaking attacker broke into a small French automotive business, planted a keylogger, and stole banking and email credentials.
Ordinary stuff, until one move near the end.
Before his command-and-control server went dark, he installed OpenSSH and Tailscale on a victim's machine, building a...
[This is a guest diary submitted by Varun Murdula]
DragonForce hid for months by routing malware traffic through Microsoft Teams infrastructure, masking C2 activity and evading network detection. DragonForce ransomware operators hit a major U.S. services firm and stayed hidden for one to two months by routing their command-and-control traffic throug...
Config-IniFiles could be made to run commands or overwrite files if it received specially crafted input.
Researchers have long warned that AI agents could lower the skill floor for offensive cyber operations, and a recent report by OALABS (Open Analysis) researchers bears that out. After recovering and analyzing over 1,000 agent sessions from a compromised server on which an attacker deployed Anthropic...
Multiple firms have observed active exploitation of the FortiSandbox defects, and warn that the attacks originate from multiple sources, not a single campaign.
The post Attackers hit pair of critical Fortinet vulnerabilities the vendor disclosed in April appeared first on CyberScoop.