L'autorité espagnole de protection des données (AEPD) a sanctionné une société pour avoir inscrit une personne dans un fichier d'incidents de paiement sans pouvoir justifier de l'existence d'un contrat fondant la dette alléguée.Faits et contexteL'autorité espagnole de protection des données (AEPD) a...
L'autorité espagnole de protection des données a sanctionné Vodafone pour un manquement à son obligation de sécurité, suite à une cyberattaque ayant affecté son sous-traitant qui n'avait pas corrigé une vulnérabilité critique connue depuis plusieurs mois, retenant ainsi la pleine responsabilité du r...
Brevo confirmed that attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites and JavaScript files embedded on customer sites to distribute malware. [...]
The Coast Guard confirmed evidence of malicious cyber activity on the VL Prosperity, but has not attributed the attack to Iran.
The post Cyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board Vessels appeared first on SecurityWeek.
AI has made fundamental changes to the operating environment for cybersecurity. Explore exposure management guidance on recommended controls and take action and stay ahead of cyberthreats.
The post From guidance to action: Security fundamentals that materially reduce risk appeared first on Microsof...
Alleged Chinese hackers are breaking into government agencies across Latin America using a new backdoor that researchers are calling “SparroWocky.”
It was discovered that libsoup incorrectly handled certain URLs when
using an HTTP proxy. A remote attacker could possibly use this issue to
inject arbitrary HTTP headers. (CVE-2026-1467)
It was discovered that libsoup did not remove proxy authentication
credentials when following HTTP redirects. A...
Découvrez Specops Verified ID, qui vérifie l'identité des utilisateurs par scan d'une pièce d'identité et liveness détection contre le vishing et les deepfakes.
Le post Specops Verified ID : votre identité réelle devient un facteur d’authentification a été publié sur IT-Connect.
The latest email security benchmarking reports show strong Microsoft Defender performance across pre-delivery and post-delivery scenarios and reveal where threats and defenses continue to evolve.
The post Improving email security outcomes with real-world Microsoft Defender insights appeared first on...
It was discovered that Bubblewrap incorrectly handled certain temporary
directories. A local attacker could possibly use this issue to cause a
denial of service or execute arbitrary code. This issue only affected
Ubuntu 18.04 LTS. (CVE-2019-12439)
It was discovered that Bubblewrap incorrectly handl...
OpenAI has published six new reports detailing AI model misalignment, including instances of hidden instructions, unauthorized communication, and attempts to locate exposed API keys, adding to the evidence that its AI systems bypassed controls during testing.
The reports, b...
OpenAI published a framework for disclosing model misalignment alongside six reports describing problematic behavior.
The post OpenAI Says Its Models Searched GitHub for Leaked API Keys During Training appeared first on SecurityWeek.
GNU Bison could be made to run programs as your login if it processed a specially crafted grammar file.
GStreamer Good Plugins could be made to consume resources if it received specially crafted network traffic.
Malicious code running inside a Docker Sandboxes virtual machine on macOS could escape the project directory shared into it and read or change files anywhere else on the host, Docker warns in a security announcement on September 15.
The escape runs with the rights of the host account that runs the...
Security budgets may be growing on paper, but for a majority of CISOs, the money isn’t moving in quite the same direction.
The budgets grew by 5% on average in 2026, up from 4% last year. But that average hides a much weaker picture: median budget growth remained at 0%. And...
City Relay says intruders accessed its Metabase Cloud instance twice and extracted customer data
ESET said FamousSparrow has replaced SparrowDoor with SparroWocky
We would never tell a police officer to face a blade with “resilience” instead of body armour, so why do we expect digital forensic investigators to face repeated trauma with little more than resilience to protect them?
At the end of August, a malspam message was caught in the quarantine of a mail gateway operated by one of my customers. The message was not especially remarkable – it asked the recipient to review some attached requirements and provide a price quotation for a fiber optic system and appeared to imp...