[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (3 articles)

|

// AI-powered summary generated at 08:00

> New Rokarolla Android malware targets 217 banking, crypto apps
A new Android banking trojan named Rokarolla is targeting 217 banking and cryptocurrency applications using an extensive set of 137 commands. [...]
> Ubuntu 20.04 LTS Linux Kernel Important Privilege Escalation Fix USN-8439-1
Several security issues were fixed in the Linux kernel.
> USN-8439-1: Linux kernel (Oracle) vulnerabilities
Stonejiajia, Shir Tamari and Sagi Tzadik discovered that the OverlayFS implementation in the Ubuntu Linux kernel did not properly perform permission checks in certain situations. A local attacker could possibly use this to gain elevated privileges. (CVE-2023-2640) Shir Tamari and Sagi Tzadik discov...
> iRhythm Hit by Cyberattack, Patient Data Stolen and Ransom Demanded
iRhythm disclosed a cyberattack via third-party apps where patient and proprietary data was stolen, followed by a ransom demand. iRhythm Technologies is a U.S.-based digital healthcare company specializing in remote cardiac monitoring and arrhythmia detection. Its best-known product is the Zio, a we...
> Debian gsasl Critical Memory Exposure Resolution DSA-6348-1
It was discovered that missing input sanitising in the NTLM client of the GNU SASL library could result in memory disclosure For the stable distribution (trixie), this problem has been fixed in version 2.2.2-1.1+deb13u2. We recommend that you upgrade your gsasl packages.
> Google Vertex AI SDK Flaw Let Attackers Hijack Model Uploads via Bucket Squatting
A flaw in the Google Cloud Vertex AI SDK for Python let an attacker with no access to a victim's project hijack the victim's machine learning model upload and run code inside Google's serving infrastructure. Palo Alto Networks Unit 42, which found and reported the bug through Google's bug bounty pr...
> Onward, Friends
After 26 years, today is my last day at EFF. It's been a terrific and wild ride — the organization has grown from a tiny band of fighty people trying to plant a flag for freedom and justice in the coming digital world into a large, established band of fighty people doing, well, much the same. The wo...
> Steam Workshop abused to spread malware via Wallpaper Engine app
Threat actors are abusing Steam Workshop, Valve's community hub for downloading game-related content, to push various malware hidden in wallpaper packages. [...]
> Three critical Fortinet sandbox bugs splattered by unknown attackers
All have patches, so make sure you upgrade to a fixed version
> Bug in FIFA World Cup internal system gave anyone ability to modify TV stream
A security researcher said a flaw in FIFA’s online platforms allowed her to access several internal systems, including one that could have allowed her to take control of the TV stream of every World Cup match.
> WordPress PBN Plugin Drops Dual Webshells via Database Injection
During a recent incident response engagement, our team uncovered a multi-stage WordPress infection that goes beyond the usual file-based malware. The attacker combined a fake plugin, a remote command-and-control server, and two PHP web shells stored directly inside the WordPress database. The campai...
> Supply chain attacks: how to protect your business from third-party risks
A supply chain attack can affect businesses of any size. Find out how to reduce exposure from vendors and SaaS tools.
> Threat tactic spotlight: Subdomain takeover
In this blog post you’ll learn how to detect and prevent subdomain takeover – a tactic where threat actors exploit dangling DNS records to redirect traffic to attacker-controlled resources. We’ll explain the issue, how the situation arises, and how you can use various AWS features and services to he...
> ‘Dangerous’ AI Models Are Coming No Matter What
The US government crackdown on Anthropic’s Claude Fable 5 and Mythos 5 hides a glaring truth: AI models with advanced hacking capabilities will soon be the norm.
> ClickFix Campaigns Expand Malware Delivery With New Loaders and Fake Update Lures
Cybersecurity researchers have flagged multiple ClickFix campaigns that deliver three malware loaders called BabaDeda Loader, Lorem Ipsum Loader, and Potemkin, per independent reports from Morphisec, BlueVoyant, and Huntress, respectively. Attacks involving BabaDeda Loader, observed in April 2026,...
> PSA: Supply Chain Compromise Targets ShapedPlugin, Backdoored Pro Plugins Distributed via Official Channels
The Wordfence Threat Intelligence Team was notified on June 11th, 2026 of a potential supply chain compromise affecting ShapedPlugin, a WordPress plugin vendor with over 400,000 active free plugin installations. Fortunately, Wordfence customers have already had malware signature detection for the pa...
> ANSPDCP - autorité roumaine
Le non-respect du droit d'opposition à la prospection commerciale directe entraßne une violation de l'obligation de licéité du traitement.Faits et contexteL'Autorité Nationale de Surveillance du Traitement des Données à CaractÚre Personnel (ANSPDCP) roumaine a publié une décision de sanction à l'enc...
> IMY - autorité suédoise
L'Autorité suédoise de protection de la vie privée (IMY) a aujourd'hui publié une décision prononçant une réprimande à l'encontre de Securitas Sverige AB pour des manquements en lien avec la vidéosurveillance de ses salariés conducteurs de véhicules.Faits et contexteL'affaire trouve son origine dans...
> Ubuntu 26.04 rabbitmq-c Critical Buffer Overflow and DoS Issues 8437-1
Several security issues were fixed in rabbitmq-c.
> CNIL
La Commission Nationale de l'Informatique et des LibertĂ©s (CNIL) a annoncĂ© la nomination de son nouveau directeur administratif et financier.À compter du 15 juin 2026, un administrateur de l'État est nommĂ© directeur administratif et financier de la CNIL, succĂ©dant Ă  son prĂ©dĂ©cesseur qui occupait cet...