[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (34 articles)

|

// AI-powered summary generated at 12:00

> Ubuntu 25.10 Kea DHCP Important Denial of Service Vulnerability USN-8403-1
Kea DHCP could be made to crash if it received specially crafted messages.
> Ubuntu 26.04 CUPS Critical Denial of Service and Access Flaws USN-8405-1
Several security issues were fixed in CUPS.
> Meta Accuses NSO of Violating WhatsApp Court Injunction
Meta says NSO violated a court injunction by targeting WhatsApp users again through phishing campaigns and test accounts. Last year, WhatsApp won a landmark case against NSO Group, the Israeli spyware vendor behind Pegasus, and secured a permanent court injunction barring the company from ever targe...
> New Shai-Hulud attack trojanizes 19 science-focused PyPI packages
Hackers compromised 19 packages on the PyPI, collectively downloaded hundreds of thousands of times, in a new Shai-Hulud supply-chain attack that delivered malware designed to steal developer secrets. [...]
> UK gives big tech 3 months to create device controls to block nude images of kids
The companies “must activate built-in features or implement technical solutions on smartphones and tablets to detect and block nude images for children,” according to a press release from the Home Office. Prime Minister Keir Starmer announced the measure in a speech at London Tech Week Monday.
> Ubuntu 26.04 LTS Inetutils Critical Privilege Escalation DoS CVE-2026-28372
Several security issues were fixed in Inetutils.
> Ubuntu 26.04 Transmission Important Clickjacking Threat USN-8404-1
Transmission could allow unintended actions if a user visited a malicious website.
> One-Character Linux Kernel Flaw Enables Local Root Access, Exploits Now Public
Security researchers have published a detailed, working exploit for a Linux kernel use-after-free that lets an unprivileged local user escalate to root and break out of a container. The flaw, CVE-2026-23111, sits in the kernel's nf_tables packet-filtering code and was patched upstream on February 5...
> Microsoft’s open source tools were hacked to steal passwords of AI developers
Microsoft shut down dozens of GitHub code repositories for Azure and AI coding tools after a reported hack.
> USN-8408-1: Twig vulnerability
It was discovered that Twig did not properly validate PHP callables when using a source policy. An authenticated user could possibly use this issue to execute arbitrary code.
> Ubuntu 25.10 Systemd Critical Arbitrary Code Exec DNS Issues USN-8402-1
Several security issues were fixed in systemd.
> Cheers to the Winners of EFF’s 18th Annual Cyberlaw Trivia Night! 
On a warm June evening in San Francisco, attorneys and other legally-minded friends of EFF gathered for our 18th Annual Cyberlaw Trivia Night, an annual test of tech-related legal knowledge, and the ability to remember some deeply obscure facts under pressure.  Returning Quizmaster Kurt Opsahl once...
> Ces trois failles offrent un accès root sur UniFi OS Server : patchez !
CVE-2026-34908, CVE-2026-34909, et CVE-2026-34910 : exploitées ensemble, ces trois failles permettent d'exécuter du code en tant que root sur UniFi OS Server. Le post Ces trois failles offrent un accès root sur UniFi OS Server : patchez ! a été publié sur IT-Connect.
> WhatsApp says it disrupted new NSO spyware phishing attacks
WhatsApp has detected and stopped spear-phishing campaigns allegedly conducted by the NSO Group after investigating user reports of social engineering attacks. [...]
> What to look for in an AI assistant
Here's what SMB founders and IT leaders should look for before connecting an AI assistant to their business data.
> Meta claims NSO Group still targets WhatsApp users despite court order
Meta claims it disrupted spear-phishing attempts linked to NSO Group and is asking a US federal court to hold the spyware vendor in contempt for allegedly violating an injunction that bars it from targeting WhatsApp and its users. “We successfully disrupted NSO-linked social engineering attempts aft...
> Ubuntu 26.04 LTS 8399-1 Pillow Denial of Service Risk CVE-2026-42308
Several security issues were fixed in Pillow.
> Ubuntu 26.04 LTS Poppler Critical DoS Code Execution Vuln USN-8400-1
poppler could be made to crash or run programs if it opened a specially crafted file.
> Meta Deletes Face-Recognition System From Its Smart Glasses App After WIRED Report
The code WIRED identified is gone from the latest version of Meta AI, the companion app for the company’s smart glasses. Meta won’t say why or whether it’s coming back.
> USN-8407-1: strongSwan vulnerability
Elliott Childre discovered that strongSwan incorrectly handled the cloning of certain identities. A remote attacker could use this issue to cause strongSwan to crash, resulting in a denial of service, or possibly execute arbitrary code.