[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (14 articles)

|

// AI-powered summary generated at 20:00

> CVE-2026-44631 Apache HTTP Server: Heap Underflow in `ap_regname` via Signed Char Overflow
Information published.
> CVE-2026-42535 Apache HTTP Server: mod_dav_fs protected directory access
Information published.
> JDY Botnet Evolves After KV Takedown, Targets Military Networks
JDY botnet scans SOHO/IoT devices globally to map services and targets, especially US military networks. Lumen’s Black Lotus Labs reported the resurgence of the JDY botnet, a covert reconnaissance network tied to Chinese state-sponsored hacking groups including Volt Typhoon. The network was first sp...
> CVE-2026-29167 Apache HTTP Server: mod_ldap per-dir use-after-free
Information published.
> CVE-2026-43951 Apache HTTP Server: OOB Read in `merge_response_headers` can cause crash
Information published.
> Microsoft corrige la faille YellowKey, il révèle GreatXML pour contourner BitLocker !
À peine la faille YellowKey corrigée, une nouvelle zero-day nommée GreatXML menace BitLocker sur les machines Windows. Voici ce que l'on sait. Le post Microsoft corrige la faille YellowKey, il révèle GreatXML pour contourner BitLocker ! a été publié sur IT-Connect.
> CVE-2026-29170 Apache HTTP Server: mod_proxy_ftp XSS
Information published.
> CVE-2026-44119 Apache HTTP Server: escalation of privilege through expressions in .htaccess in multiple modules
Information published.
> Nottingham University data breach affects over 450,000 students
The University of Nottingham confirmed on Wednesday that a hacking group gained access to its student records system in a breach affecting both current students and alums. [...]
> CVE-2026-48913 Apache HTTP Server: mod_http2 memory corruption when file handles exhausted
Information published.
> CVE-2026-10846 Insufficient verification that responses belong to a query
Information published.
> Ubuntu 26.04 LTS libcrypt-saltedhash Important Salt Weakness USN-8418-1
Crypt-SaltedHash incorrectly generated random numbers.
> CVE-2026-11824 SQLite before 3.53.2 Heap Buffer Overflow via FTS5 fts5ChunkIterate
Information published.
> CVE-2026-46433 lldpd: Heap OOB Read in VLAN Decapsulation memmove
Information published.
> Every employee’s password was stored in a single Excel file
The CEO thought this was the best way to deal with some email issues
> CVE-2026-42536 Apache HTTP Server: mod_xml2enc heap overflow
Information published.
> CVE-2026-11822 SQLite before 3.53.2 Memory Corruption in FTS5 Extension
Information published.
> USN-8420-1: .NET vulnerabilities
It was discovered that .NET did not properly handle link resolution before file access. A local attacker could use this issue to perform unauthorized file tampering and write arbitrary files outside of the intended extraction directory. (CVE-2026-45491) It was discovered that .NET did not properly...
> Microsoft Patches Exploited Exchange Server Vulnerability
The company warned about zero-day attacks exploiting the Exchange Server vulnerability CVE-2026-42897 on May 14.  The post Microsoft Patches Exploited Exchange Server Vulnerability appeared first on SecurityWeek.
> GitHub to Disable npm Install Scripts by Default to Stop Supply Chain Attacks
GitHub has announced what it said are "breaking changes" coming to npm version 12, one of which turns off install scripts by default to combat software supply chain threats. The changes aim to combat attack techniques that abuse the "npm install" command to trigger the execution of malicious code u...