[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (14 articles)

|

// AI-powered summary generated at 20:00

> Max severity Ivanti Sentry vulnerability now exploited in attacks
Attackers are now targeting a recently patched maximum-severity flaw in Ivanti Sentry, enabling them to execute code with root privileges on Internet-exposed secure mobile gateways. [...]
> Threat actors are recruiting the people who hold cloud logins
Companies keep most of their data and applications in cloud platforms that anyone can reach with the right login. That setup turns each employee holding those credentials into a security variable, and members of the cybercrime underground have built methods to reach those people. Intel 471 tracked t...
> Debian libinput Important Local Privilege Escalation Vuln DSA-6339-1
It was discovered that a udev helper provided by libinput, a input device management and event handling library, performed insufficient sanitising of device properties, which can result in local privilege escalation in some setups. For the oldstable distribution (bookworm), this problem has been fix...
> Making the cloud prove it followed your privacy wishes
Making companies that store personal data in cloud key-value databases handle deletion requests by running the operation and confirming the job is complete. The people making those requests and the regulators overseeing them have had limited means to confirm the data is gone or that the record of it...
> Debian libdbi-perl Critical Denial of Service Code Exec DSA-6338-1
Two vulnerabilities were discovered in libdbi-perl, a Perl framework that provides a common interface to access various backend databases in a uniform manner, which may result in denial of service, or potentially the execution of arbitrary code. For the oldstable distribution (bookworm), these probl...
> Windows : RoguePlanet, une faille zero-day dévoilée juste après les mises à jour de juin
RoguePlanet, une faille zero-day ciblant Windows Defender et permettant d'obtenir les privilèges SYSTEM sur Windows, a été publiée par Nightmare Eclipse. Le post Windows : RoguePlanet, une faille zero-day dévoilée juste après les mises à jour de juin a été publié sur IT-Connect.
> ZDI-26-356: Apache HTTP Server mod_proxy_ajp Out-Of-Bounds Read Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Apache HTTP Server. An attacker must first obtain the ability to compromise an AJP backend associated with the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS r...
> ZDI-26-357: Allegra exportReport Directory Traversal Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Allegra. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.5. The following CVEs are assigned: CVE-2026-11442.
> CrowdStrike Named an Innovation and Growth Leader in the 2026 Frost Radar™: Cloud and Application Runtime Security
> ZDI-26-358: Allegra downloadAttachment Cross-Site Scripting Authentication Bypass Vulnerability
This vulnerability allows remote attackers to execute arbitrary script on affected installations of Allegra. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 4.6. The following CV...
> ZDI-26-359: Samsung rlottie Numeric Truncation Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Samsung rlottie. Interaction with the rlottie library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 7.8. Th...
> Prompt injection still drives most agentic AI security failures in production
A backdoor sat on PyPI for three hours in March 2026. Nearly 47,000 downloads occurred during the window. The compromised package, LiteLLM, serves as the language-model gateway for CrewAI, DSPy, Microsoft GraphRAG, and dozens of other AI agent frameworks. Anyone pulling an update during that window...
> ZDI-26-360: MATE Desktop Atril Document Viewer EPUB File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of MATE Desktop Atril Document Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating...
> X Square Robot open sources its robot-free data collection framework
Companies building robots for physical work spend large amounts of time and money operating machines by hand to gather training examples. Each session with a physical robot produces a small number of demonstrations per day, which slows the growth of datasets used to train embodied AI. Human demonstr...
> Organizations can’t see much of their mobile AI activity
Organizations have limited visibility into AI activity on mobile devices despite security leaders expressing confidence in their AI governance, according to Lookout’s “Solving for the Mobile AI Blind Spot: Executive Confidence Meets Technical Reality” report. Mobile AI visibility gaps Enterprises la...
> ISC Stormcast For Thursday, June 11th, 2026 https://isc.sans.edu/podcastdetail/9968, (Thu, Jun 11th)
> GitHub finally pulls the plug on automatic install script execution for npm
The ability for attackers to leverage automatic install script execution in npm will finally come to an end when expected changes arrive from GitHub in July. Coders will still be able to enable the function, but the default setting will block it.  In V12, default settings a...
> Prince George County
Le comté de Prince George en Virginie a été victime d'un incident de cybersécurité qui a perturbé son système d'information à partir du 11 juin 2026. L'attaque a affecté les services téléphoniques, Internet et de paiement en ligne, tandis que les services d'urgence 911 et de dispatch de la sécurité...
> June Patch Tuesday smashes past 500-CVE mark
209 patches + 388 advisories = welcome to summer 2026
> National Association of Insurance Commissioners (NAIC)
La National Association of Insurance Commissioners (NAIC) a été victime d'une cyberattaque le 11 juin, exploitant une vulnérabilité zero-day dans ses systèmes Oracle PeopleSoft. Le groupe d'extorsion ShinyHunters a revendiqué l'attaque. La NAIC a confirmé que des informations réglementaires sensible...