> TODAY'S SUMMARY (114 articles)
Today's cybersecurity landscape reveals several critical threats and trends. A member of the ShinyHunters hacking group has been detained in Jordan, cooperating with the FBI amid ongoing investigations into a significant data breach involving employee information. Meanwhile, vulnerabilities in Citrix NetScaler and Rejetto HFS have been actively exploited, with warnings from CISA regarding their severity and potential impact. Additionally, Denmark's population registry suffered a breach affecting 8.8 million individuals, raising concerns about data security in governmental databases. In the healthcare sector, IQVIA faced a hefty fine for inadequate data anonymization, underscoring the ongoing scrutiny over data protection practices. Lastly, Google has paused its open-source bug bounty program due to an influx of invalid AI-generated reports, reflecting challenges in managing AI vulnerabilities.
|
// AI-powered summary generated at 20:00
Codex drops an HTTP/2 Bomb
New libinput packages are available for Slackware 15.0 and -current to fix a security issue.
New dnsmasq packages are available for Slackware 15.0 and -current to fix a security issue.
A data breach at the dental benefits administrator DentaQuest has reportedly exposed the sensitive data of 2.6 million accounts. [...]
New research details how the increasing integration of AI agents into businesses is making it easier than ever for insiders - malicious or otherwise - to put sensitive data at risk.
The post Your AI agent could become your biggest insider threat appeared first on CyberScoop.
The groups have previously claimed responsibility for cyberattacks targeting critical infrastructure and government institutions in Russia and Belarus.
Joe’s on-the-ground report from Cisco Live U.S. is here, complete with therapy dog pictures and tips on handling conference overstimulation.
La Commission nationale de l'informatique et des libertés (CNIL) a rendu public l'ordre du jour de sa séance plénière du 4 juin 2026.
Partie I (avec débats): :
* Communication : « La confidentialité dans l’euro numérique : où en sommes-nous ? » ;
* Lunettes connectées : point d’information...
L'autorité islandaise de protection des données (Persónuvernd) a finalisé ses audits sur le traitement des données personnelles par les autorités de poursuite du pays, incluant le procureur général, les procureurs de district et les chefs de police.Ces audits ont été initiés suite à des révélations...
Code reviewed by WIRED uncovered an unreleased face-recognition system embedded in Meta’s smart glasses platform. It’s designed to identify people via biometric data stored on users’ phones.
L'Agence espagnole de protection des données (AEPD) a publié une décision de sanction à l'encontre de VERTI ASEGURADORA, COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A. (comprenant le prononcé d'une amende de 4 000 €) pour des manquements en lien avec l'envoi de communications commerciales par voie électroni...
Le Bureau du Commissaire à l'information (ICO) a obtenu des ordonnances de confiscation pour un montant total de 118 852,32 £ (environ 140 246 €) à l'encontre de deux anciens employés de la société RAC.Ces ordonnances, prises en application de la Loi sur les produits de la criminalité (POCA), font s...
The Trump administration had backed the FCC’s position and, apart from Justice Clarence Thomas, the high court agreed.
L'autorité norvégienne de protection des données (Datatilsynet) a publié une décision de sanction à l'encontre d'Elkjøp, comprenant le prononcé d'une amende de 20 000 000 de couronnes norvégiennes (environ 1 760 000 €), pour des manquements en lien avec le traitement de données personnelles au sein...
L'autorité néerlandaise de protection des données a officialisé sa procédure de surveillance renforcée, un instrument de contrôle préventif destiné à améliorer la conformité au RGPD.Cette forme de contrôle, plus intensive que la surveillance habituelle, est mise en œuvre lorsqu'une procédure de sanc...
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Mirasvit Full Page Cache Warmer flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Mirasvit Full Page Cache Warmer flaw, tracked as CVE-2026-45247 (CVSS ver 4.0...
L'autorité hellénique de protection des données a émis un avis sur un projet de décret présidentiel du ministère de la Marine et de la Politique insulaire concernant la création d'un système électronique centralisé pour le transport maritime.Le projet vise à mettre en place un Système Électronique d...
L'autorité espagnole de protection des données (AEPD) a publié une décision déclarant la péremption de la procédure de sanction engagée à l'encontre de TELEFÓNICA AUDIOVISUAL DIGITAL, S.L. pour des manquements allégués en lien avec la diffusion de l'image d'une personne. Cette affaire débute par une...
Michał Majchrowicz and Marcin Wyczechowski discovered that Nano created
the ~/.local directory with incorrect permissions. In environments with
permissive umask settings, a local attacker could possibly use this
issue to inject a malicious launcher file, resulting in information
disclosure or other...
Cisco has patched a bug in Unified Communications Manager that lets an unauthenticated attacker on the network write files to the box and, from there, climb to root.
It is tracked as CVE-2026-20230, and proof-of-concept exploit code is already public. Cisco's PSIRT says it has not seen the flaw use...