[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (14 articles)

|

// AI-powered summary generated at 20:00

> Debian jackson-core Important DoS Attack Risk DSA-6336-1 CVE-2025-52999
A flaw was discovered in jackson-core, a fast and powerful JSON library for Java, which may allow an attacker to cause a denial of service by using deeply nested JSON data. Please note that related and complementary jackson-* packages like jackson- databind or jackson-dataformat-smile had to be upgr...
> CISA Tells US Agencies to Fix Security Bugs in as Little as 3 Days Thanks to AI Threats
“Defenders cannot afford to take weeks to patch,” one Cybersecurity and Infrastructure Security Agency official warned on Wednesday.
> Trump Risks Key Surveillance Authority Over ‘Unqualified’ Spy-Chief Pick
US lawmakers are alarmed that Bill Pulte, a housing official with no intelligence experience, is poised to take charge of one of the government's most powerful surveillance tools.
> The ‘Miasma’ worm source code briefly leaked on GitHub
The Miasma credential-stealing attack framework, which has recently targeted open-source ecosystems through supply-chain attacks, was briefly open-sourced on GitHub. [...]
> CISA tells agencies to patch smarter, not harder — foreshadowing broader industry practice
Security teams’ patching practices have come under intense pressure over the past year, as active exploitation is up, time-to-exploit windows are accelerating, and vulnerabilities have become attackers’ top initial access vector of choice. Last year, organizations fully rem...
> OpenAI: ‘Likely’ Chinese influence operation tried to use ChatGPT to stir debate on data centers 
The company says there’s little evidence it influenced any real policy discussion.  The post OpenAI: ‘Likely’ Chinese influence operation tried to use ChatGPT to stir debate on data centers  appeared first on CyberScoop.
> Ivanti patches critical Sentry flaws that lead to full device takeover
IT software provider Ivanti fixed two vulnerabilities in Ivanti Sentry, a secure mobile gateway appliance formerly called MobileIron Sentry. The flaws could allow unauthenticated remote attackers to gain complete control of deployments. One of the vulnerabilities, CVE-2026-...
> Oracle Linux Important Kernel Update ELSA-2026-50304 CVE-2025-10263
The following updated rpms for have been uploaded to the Unbreakable Linux Network:
> Oracle Linux 9 ELSA-2026-50304 Major Kernel Security Update Available
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
> North Koreans behind nearly half of US tech industry hacks, says CrowdStrike
North Koreans hackers posing as remote IT workers and recruiters remain a major threat to U.S., European, and Asian companies, accounting for about half of all attacks over the past 12 months.
> Oracle Linux 8 libyang Important DoS Threat ELSA-2026-24545
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
> Oracle Linux 8 frr Important Fix for CVE-2026-37457 ELSA-2026-24340
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
> CISA to require federal agencies to patch some cyber vulnerabilities within 3 days
CISA is giving agencies 180 days to adopt the new patching time frame, according to a directive released Wednesday.
> Oracle Linux 8 ELSA-2026-24365 Unbound Important Security Advisory
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
> Oracle Linux 7 Kernel Important Security Fix ELSA-2026-50306
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
> GitHub announces npm security changes to tackle supply-chain attacks
GitHub has announced that npm v12, expected next month, will introduce several security-focused changes aimed at blocking supply-chain attacks abusing behaviors triggered by the 'npm install' command. [...]
> The 702 Ultimatum: Warrant Requirement or Bust
For months now, Congress has been kicking the ball down the road—temporarily postponing the expiration of the mass surveillance authority Section 702 of FISA in hopes that some consensus could be reached. Now, with the deadline looming, the stakes have never been higher. Nearly every time the statut...
> Ubuntu 24.04 8409-1 Uriparser Important Denial of Service
uriparser could be made to crash if it received specially crafted input.
> Angry bug hunter with Microsoft beef drops new Windows 0-day
Revenge is a dish best served code
> Oracle PeopleSoft servers hacked in ShinyHunters data theft attacks
Oracle PeopleSoft servers are being targeted in ongoing data theft attacks by the ShinyHunters extortion gang, which claims to have stolen data from over 100 organizations. [...]