Several security issues were fixed in Samba.
Enshittification isn't just a sweary word to describe the accelerating decay of the online platforms, apps, and services that we rely on. Â
It's a framework for understanding the structural incentives that make tech companies enemies of their own users over time—the surveillance business model, the...
Across the country, surveillance companies have spun a vast web of tens of thousands of license plate cameras. The people selling this tech want you to believe that it's for your safety, but how are authorities really using automated license plate readers (ALPR)? In this week's EFFector newsletter,...
La Commission nationale de l'informatique et des libertés (CNIL) détaille les règles applicables aux communications électroniques destinées aux prospects et aux clients, en distinguant la prospection commerciale des messages transactionnels et relationnels.La prospection commerciale par voie électro...
Le Comité européen de la protection des données (CEPD) a échangé avec le Commissaire européen sur plusieurs sujets de conformité et a adopté un modèle commun de notification de violation de données personnelles.Lors de sa session plénière, le Comité a échangé avec Michael McGrath, Commissaire à la d...
On June 2nd, 2026, we received a submission for a critical Unauthenticated Authentication Bypass vulnerability in UpdraftPlus, a WordPress plugin with more than 3 million active installations. Although the plugin has such a large install base, the vulnerability is only exploitable on sites that have...
Le Préposé fédéral allemand à la protection des données et à la liberté d'information (BfDI) a exprimé ses critiques concernant le projet de règlement "Omnibus Numérique" de la Commission européenne, estimant qu'il n'aborde pas suffisamment plusieurs questions centrales en matière de protection des...
HTTP-Daemon could be made to run programs if it received specially crafted network traffic.
Cybercriminals are turning TikTok and Instagram Reels into malware delivery platforms, using free software tutorials to spread infostealers.
Cybersecurity researchers have warned of a "resurgence and expansion" of JDY, a covert network associated with China-nexus state-sponsored threat actors.
"The JDY botnet comprises over 1,500 SOHO [small office and home office] and IoT devices and operates as a centrally controlled, high-performance...
A vulnerability that meets all four criteria would need to be fixed within three days, for instance.
The post CISA directive orders agencies to prioritize vulnerability patching in a new way appeared first on CyberScoop.
Adaptive Spec-driven Scoring for Evaluation and Regression Testing (ASSERT) is an open-source framework for converting natural language behavior requirements into executable evaluations of AI models and agents.
The post Turn specs into evals for any agent with ASSERT appeared first on Microsoft Secu...
Threat actors push fake free-software tutorials on TikTok and Instagram to spread Vidar stealer
Cybersecurity researchers are complaining that Anthropic's new model Fable has guardrails that are too strict for any cybersecurity work.
Menlo Security research warns that as enterprise applications become increasingly browser based, traditional cybersecurity tools leave them vulnerable to cyber threats
MaaS trojan SilabRAT uses HVNC and browser cloning to hijack sessions and steal crypto
Australia's second-largest sugar producer said on Wednesday that it was responding to a cybersecurity incident affecting parts of its operations and had engaged cybersecurity experts and local authorities to investigate the attack and restore its systems safely.
Fortinet, Ivanti, and SAP have released security updates to address multiple critical security vulnerabilities that could result in arbitrary code execution and information disclosure.
The security flaw patched by Fortinet relates to a command injection vulnerability in FortiSandbox, FortiSandbox C...
A high-severity unpatched security flaw in Langflow, an open-source low-code platform to build artificial intelligence (AI) applications, has come under active exploitation in the wild, according to findings from VulnCheck.
The vulnerability in question is CVE-2026-5027 (CVSS score: 8.8), a case of...
The JDY botnet, a malware network previously associated with Chinese threat actors like Volt Typhoon, has significantly expanded its targeting scope and reconnaissance efforts. [...]