[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (87 articles)

|

// AI-powered summary generated at 16:00

> C0XMO botnet spreads via DD-WRT router flaw, kills rival malware
A new variant of the Gafgyt botnet called C0XMO is targeting DD-WRT router firmware and can move to other device types with various CPU architectures. [...]
> Silent Ransom Group targets law firms with fake IT support calls
The Silent Ransom Group extortion gang is actively targeting U.S. law firms and professional services organizations in social engineering attacks that often lead to data theft within hours of initial contact, according to a new report by cybersecurity firm Mandiant. [...]
> Emphere Raises $2.1 Million for AI-Powered Vulnerability Remediation
Emphere’s solution delivers AI-driven remediation to software companies to speed up releases. The post Emphere Raises $2.1 Million for AI-Powered Vulnerability Remediation appeared first on SecurityWeek.
> CVE-2026-42504 Quadratic complexity in WordDecoder.DecodeHeader in mime
Information published.
> Week in review: Cisco SD-WAN 0-day exploited, Patch Tuesday forecast
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: OWASP Agent Memory Guard: Stop AI agents from being weaponized through their own memory Agent Memory Guard is an open-source runtime defense layer that sits between an agent and its memory store, screen...
> Baker Distributing - 102,935 breached accounts
In May 2026, the HVAC/R wholesale distributor Baker Distributing Company was added to the ShinyHunters data extortion group's "pay or leak" site. In early June, the group publicly published data they claimed had been obtained from Baker's SharePoint and Salesforce infrastructure including 103k uniqu...
> Toulouse Football Club
Le Toulouse Football Club a été informé par l'un de ses prestataires d'un incident de sécurité affectant une infrastructure de sauvegarde de données. Le club a immédiatement activé ses protocoles de crise, sécurisé ses systèmes et a notifié la CNIL ainsi que les autorités compétentes. Bien qu'aucune...
> Novo Nordisk
Le géant pharmaceutique Novo Nordisk a été victime d'une cyberattaque majeure revendiquée par le groupe FulcrumSec. L'intrusion a duré environ deux mois et demi, débutant par l'exploitation d'un jeton d'accès GitHub exposé. Des données "pseudo-anonymisées" (sans noms directs) de 11 500 participants...
> U.S. CISA adds SolarWinds Serv-U flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds SolarWinds Serv-U flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added SolarWinds Serv-U flaw, tracked as CVE-2026-28318 (CVSS ver 3.1 score of 7.5), to its Known...
> Evanston Township High School District 202
Le district scolaire Evanston Township High School 202 a été victime d'une attaque par ransomware le 7 juin 2026, perturbant les systèmes du district, les services internet et l'infrastructure informatique. En conséquence, l'école est fermée les 8 et 9 juin 2026, et toutes les activités prévues sur...
> Retelit
Retelit, un important opérateur italien de télécommunications et de services cloud, a été victime d'une grave cyberattaque perpétrée par le groupe criminel Qilin. L'attaque a compromis les serveurs et permis le vol d'au moins 300 gigaoctets de documents internes, notamment des passeports et des info...
> OpenAI unveils Lockdown Mode to protect sensitive data from prompt injection attacks
Even with Lockdown Mode, ChatGPT could be still vulnerable to prompt injections, but the goal is to reduce the likelihood that sensitive data gets shared in the process.
> Debian's Request Tracker 5 SQL Injection Vulnerability Leads to DSA-6324-1
Multiple vulnerabilities have been discovered in Request Tracker, an extensible trouble-ticket tracking system, which could result privilege escalation, information disclosure, SQL injections, LDAP authentication bypass, cross-site scripting or spreadsheet (CSV/formula) injection. For the oldstable...
> Debian Apache2 Important Denial of Service DoS CVE-2026-49975 DSA-6323-1
It was discovered that incorrect cookie header accounting in the HTTP/2 implementation of the Apache HTTP server may result in denial of service (excessive resources consumption). For the oldstable distribution (bookworm), this problem has been fixed in version 2.4.67-1~deb12u3.
> WinCalls : l’appli mobile qui bloque les démarcheurs à votre place
Marre des appels spam sur votre téléphone ? WinCalls bloque les arnaques et le démarchage téléphonique de façon automatique et efficace sur Android. Le post WinCalls : l’appli mobile qui bloque les démarcheurs à votre place a été publié sur IT-Connect.
> Report: Anthropic Deploys Engineers to Support NSA Use of Mythos
Reports claim Anthropic engineers are helping the NSA use its restricted AI model Mythos, known for advanced cybersecurity capabilities. This week, the Financial Times reported that Anthropic has placed approximately six “forward-deployed” engineers inside the National Security Agency to help the in...
> Critical Everest Forms Pro flaw exploited to take over WordPress sites
Hackers are actively exploiting a critical vulnerability (CVE-2026-3300) in the Everest Forms Pro plugin, which lets them take complete control of a WordPress website. [...]
> New ChatGPT Lockdown Mode Limits Tools That Could Enable Data Exfiltration
OpenAI has begun rolling out a new Lockdown Mode to ChatGPT for eligible personal accounts to reduce the risk of data exfiltration arising from prompt injection attacks. The feature is primarily designed for people and organizations that handle sensitive data and require stricter protection guarant...
> Crypto-Funded Chinese Peptide Labs Are Booming
Plus: Hackers use Meta’s AI bots to hack Instagram accounts, Anthropic helps NSA hackers, a decades-long GPS satellite mystery may have been solved, and more.
> Opal Security Raises $23 Million for AI-Native Identity Governance
Raising $59 million to date, Opal also announced five senior leadership appointments. The post Opal Security Raises $23 Million for AI-Native Identity Governance appeared first on SecurityWeek.